{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.94-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.10-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  fsnotify: fix inode reference leak in fsnotify_recalc_mask()  fsnotify_recalc_mask() fails to handle the return value of __fsnotify_recalc_mask(), which may return an inode pointer that needs to be released via fsnotify_drop_object() when the connector's HAS_IREF flag transitions from set to cleared.  This manifests as a hung task with the following call trace:    INFO: task umount:1234 blocked for more than 120 seconds.   Call Trace:    __schedule    schedule    fsnotify_sb_delete    generic_shutdown_super    kill_anon_super    cleanup_mnt    task_work_run    do_exit    do_group_exit  The race window that triggers the iref leak:    Thread A (adding mark)              Thread B (removing mark)   ──────────────────────              ────────────────────────   fsnotify_add_mark_locked():     fsnotify_add_mark_list():       spin_lock(conn-\u003elock)       add mark_B(evictable) to list       spin_unlock(conn-\u003elock)     return      /* ---- gap: no lock held ---- */                                        fsnotify_detach_mark(mark_A):                                         spin_lock(mark_A-\u003elock)                                         clear ATTACHED flag on mark_A                                         spin_unlock(mark_A-\u003elock)                                         fsnotify_put_mark(mark_A)      fsnotify_recalc_mask():       spin_lock(conn-\u003elock)       __fsnotify_recalc_mask():         /* mark_A skipped: ATTACHED cleared */         /* only mark_B(evictable) remains */         want_iref = false         has_iref = true  /* not yet cleared */         -\u003e HAS_IREF transitions true -\u003e false         -\u003e returns inode pointer       spin_unlock(conn-\u003elock)       /* BUG: return value discarded!        * iput() and fsnotify_put_sb_watched_objects()        * are never called */  Fix this by deferring the transition true -\u003e false of HAS_IREF flag from fsnotify_recalc_mask() (Thread A) to fsnotify_put_mark() (thread B).",
  "id": "DEBIAN-CVE-2026-52990",
  "modified": "2026-09-14T16:47:46.813382907Z",
  "published": "2026-06-24T17:17:09.833Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-52990"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-52990"
  ]
}