Answer in brief
CVE-2026-72034 records a High severity (CVSS 7.8) vulnerability in fhandle: reject detached mounts in capable_wrt_mount(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=620c266f394932e5decc4b34683a75dfc59dc2f4 <15104234c267ebe04b9f9a73e5c2179cc265ff60 || >=620c266f394932e5decc4b34683a75dfc59dc2f4 <6c52226072a3c61337b1eec1799bb987748884fa || >=620c266f394932e5decc4b34683a75dfc59dc2f4 <6ee183d89261bf1d1cf9f06d80a40dab8f36ee55 || >=620c266f394932e5decc4b34683a75dfc59dc2f4 <6c732471740bc2ac9b0946134f9f551dc75f4369 | 15104234c267ebe04b9f9a73e5c2179cc265ff60, 6c52226072a3c61337b1eec1799bb987748884fa, 6ee183d89261bf1d1cf9f06d80a40dab8f36ee55, 6c732471740bc2ac9b0946134f9f551dc75f4369 |
| Linux/Linuxgeneric | 6.11 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: fhandle: reject detached mounts in capable_wrt_mount() The recent fhandle RCU fix moved the mount namespace capability check into capable_wrt_mount(), so a non-NULL mnt_namespace survives the ns_capable() dereference. The helper still assumes the later READ_ONCE(mount->mnt_ns) must be non-NULL because may_decode_fh() checked is_mounted() first. That assumption is not stable. A detached mount from open_tree(..., OPEN_TREE_CLONE) can be dissolved on fput while open_by_handle_at() is between those checks, and umount_tree() can clear mount->mnt_ns. If the helper observes NULL, it dereferences mnt_ns->user_ns and panics. Return false when the RCU read observes a detached mount. This keeps the relaxed permission path conservative: a mount no longer attached to a namespace cannot authorize open_by_handle_at() access.
Quoted source text, attributed separately from HOL analysis.