CVE-2026-90318: fat: release buffer head after rebuilding parent
Published Sep 17, 2026
·Updated
fat: release buffer head after rebuilding parent
Affected Software
2 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.152.1-1<6.6.157.1-1
6.6.157.1-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.157.1-1
Event History
Sep 17, 2026
CVE Published
via MITRE·04:08 PM
Data Sourced
via MITRE·04:08 PM
Description
Data Sourced
via NVD·05:17 PM
Description
Sep 19, 2026
Data Sourced
via Microsoft·08:14 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:14 AM
Affected Software
Updated
via Microsoft·08:14 AM
DescriptionSeverity
Frequently Asked Questions
1
Which systems are exposed to this issue?
Systems using the Linux kernel FAT filesystem and the nostale_ro NFS export path can reach the affected parent-inode rebuild logic.
2
Under what condition does the resource leak occur?
The leak occurs after fat_scan_logstart() successfully finds the matching directory entry and fat_rebuild_parent() rebuilds the parent inode without releasing the buffer head retained in sinfo.bh.