Junglewise Threat Intelligence

CVE-2026-45961: Linux Kernel GFS2 memory leaks in gfs2_fill_super error path

CVE-2026-45961 · Severity: info · CVSS 2.1 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's GFS2 file system component can lead to memory leaks when the system fails to mount or transition a file system to read-write mode. Over time, these leaks could consume system memory, potentially leading to reduced performance or system instability. This issue primarily affects servers using the Global File System 2 (GFS2) in clustered environments.

Technical details

The GFS2 (Global File System 2) implementation in the Linux kernel contains two memory leaks within the gfs2_fill_super() error handling path. The first leak occurs when gfs2_freeze_lock_shared() fails after init_threads() has already succeeded; the kernel threads (logd and quotad) are not destroyed because the 'fail_per_node' label lacks a call to gfs2_destroy_threads(). The second leak involves an 8192-byte quota bitmap buffer that remains allocated if gfs2_make_fs_rw() fails after gfs2_quota_init() succeeds. An attacker with the ability to trigger specific mount or filesystem state transition failures could cause the kernel to exhaust memory over time. Patches have been released to ensure proper cleanup of threads and quota buffers in these error paths.

Affected products

  • Linux Linux Kernel n/a

Timeline

  • 2026-02-03: patched: Initial fix committed to mainline kernel
  • 2026-05-27: advisory: CVE-2026-45961 published

References