PT-2026-51884 · Linux+2 · Linux Kernel+2

CVE-2026-52990

·

Published

2026-06-24

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An inode reference leak exists in the fsnotify subsystem. The function fsnotify recalc mask() fails to handle the return value of fsnotify recalc mask(), which may return an inode pointer that requires release via fsnotify drop object() when the connector's HAS IREF flag transitions from set to cleared. This issue can be triggered by a race condition between adding and removing marks, potentially resulting in a hung task during super block deletion.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-90509
CVE-2026-52990
ECHO-A9E9-E72F-D39A
OESA-2026-3454
OESA-2026-3455
USN-8566-1
USN-8567-1
USN-8568-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8593-1
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8618-1
USN-8619-1
USN-8663-1
USN-8664-1
USN-8665-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu