PatchSiren cyber security CVE debrief
CVE-2026-72368 Linux CVE debrief
The Linux kernel vulnerability, CVE-2026-72368, is caused by a double unlock in the nomem_d_alloc error path of cachefiles_get_directory(). This vulnerability affects Linux kernel users and could potentially lead to a denial-of-service or privilege escalation if exploited. The CVE record was published on 2026-08-15T06:22:10.227Z and has not been modified since then. Users should verify their kernel version and apply patches if available. The vulnerability has a CVSS score and severity that are currently null. The affected product or component is the Linux kernel, and the vulnerability class is related to cachefiles. The likely operational impact is a denial-of-service or privilege escalation. The source-confidence limits are based on the CVE record and the NVD detail. The review context is limited to the supplied source corpus.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel users and administrators, Linux distribution maintainers, and security teams should be aware of this vulnerability and take steps to mitigate it. Affected operators include Linux kernel developers and users. Affected platforms include Linux-based systems. Vulnerability-management teams should verify their kernel version and apply patches if available. Security teams should monitor Linux kernel updates for patches and consider implementing compensating controls to mitigate potential exploitation. Asset inventory teams should track Linux kernel deployments and prioritize patching based on risk and exposure. The vulnerability affects Linux kernel users and could potentially lead to a denial-of-service or privilege escalation if exploited. Users should verify their kernel version and apply patches if available. The vulnerability has a CVSS score and severity that are currently null. The affected product or component is the Linux kernel, and the vulnerability class is related to cachefiles. The likely operational impact is a denial-of-service or privilege escalation. The source-confidence limits are based on the CVE record and the NVD detail. The review context is limited to the supplied source corpus. Linux kernel users and administrators should take steps to mitigate this vulnerability, including verifying their kernel version and applying patches if available. Linux distribution maintainers should also be aware of this vulnerability and take steps to mitigate it, including updating their kernel versions and providing patches to their users. Security teams should monitor Linux kernel updates for patches and consider implementing compensating controls to mitigate potential exploitation. Asset inventory teams should track Linux kernel deployments and prioritize patching based on risk and exposure. Vulnerability-management teams should verify their kernel version and apply patches if available. Linux kernel developers should also be aware of this vulnerability and take steps to mitigate it, including updating their kernel versions and providing patches to their users. The vulnerability affects Linux kernel users and could potentially lead to a denial-of-
Technical summary
The vulnerability is caused by a double unlock in the nomem_d_alloc error path of cachefiles_get_directory(). When start_creating() fails and returns -ENOMEM, it has already released the parent directory lock in __start_dirop(). However, the nomem_d_alloc error path in cachefiles_get_directory() unconditionally calls inode_unlock(d_inode(dir)) again, causing a double unlock that corrupts the rwsem state.
Defensive priority
This vulnerability affects the Linux kernel and could potentially lead to a denial-of-service or privilege escalation if exploited. Users should verify their kernel version and apply patches if available.
Recommended defensive actions
- Verify kernel version and apply patches if available
- Monitor Linux kernel updates for patches
- Consider implementing compensating controls to mitigate potential exploitation
- Perform vulnerability scanning to identify exposed assets
- Review and update asset inventory to track Linux kernel deployments
- Implement monitoring and detection to identify potential exploitation attempts
- Track and document remediation efforts and exceptions
Evidence notes
The vulnerability is caused by a double unlock in the nomem_d_alloc error path of cachefiles_get_directory(). When start_creating() fails and returns -ENOMEM, it has already released the parent directory lock in __start_dirop(). However, the nomem_d_alloc error path in cachefiles_get_directory() unconditionally calls inode_unlock(d_inode(dir)) again, causing a double unlock that corrupts the rwsem state.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72368 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72368
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72368 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72368
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/26757dac15175f2a42e3537f1ba86e62456d48f1
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8c256fba2b46020004201c500b2a1fbc707a33ef
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.