Junglewise Threat Intelligence

CVE-2026-89576: Linux kernel dm-era metadata block leak on snapshot failure

CVE-2026-89576 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's dm-era component manages snapshots of block device metadata used in certain storage configurations. A bug in the snapshot creation process can leave allocated metadata blocks unreleased when an operation fails, causing permanent loss of available storage space. Repeated snapshot failures result in cumulative metadata storage exhaustion.

Technical details

A resource leak exists in the metadata_take_snap() function within the dm-era target driver. When dm_tm_shadow_block() allocates a new metadata block for a snapshot and subsequent dm_sm_inc_block() calls fail, the newly allocated shadow block is not properly freed by calling dm_sm_dec_block(). This causes each failed take-snap operation to permanently leak one metadata block from the storage pool. The fix adds dm_sm_dec_block() calls on the error paths to match the cleanup performed in metadata_drop_snap(). The vulnerability requires the dm-era target to be in use and a failed snapshot operation to occur.

Affected products

  • Linux Linux kernel all versions with dm-era target

Timeline

  • 2026-09-11: disclosed
  • 2026-08-06: patched

References

Related threats