Answer in brief
CVE-2026-72034 records a Unknown severity vulnerability in fhandle: reject detached mounts in capable_wrt_mount(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=620c266f394932e5decc4b34683a75dfc59dc2f4 <15104234c267ebe04b9f9a73e5c2179cc265ff60 || >=620c266f394932e5decc4b34683a75dfc59dc2f4 <6c52226072a3c61337b1eec1799bb987748884fa || >=620c266f394932e5decc4b34683a75dfc59dc2f4 <6ee183d89261bf1d1cf9f06d80a40dab8f36ee55 || >=620c266f394932e5decc4b34683a75dfc59dc2f4 <6c732471740bc2ac9b0946134f9f551dc75f4369 | 15104234c267ebe04b9f9a73e5c2179cc265ff60, 6c52226072a3c61337b1eec1799bb987748884fa, 6ee183d89261bf1d1cf9f06d80a40dab8f36ee55, 6c732471740bc2ac9b0946134f9f551dc75f4369 |
| Linux/Linuxgeneric | 6.11 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: fhandle: reject detached mounts in capable_wrt_mount() The recent fhandle RCU fix moved the mount namespace capability check into capable_wrt_mount(), so a non-NULL mnt_namespace survives the ns_capable() dereference. The helper still assumes the later READ_ONCE(mount->mnt_ns) must be non-NULL because may_decode_fh() checked is_mounted() first. That assumption is not stable. A detached mount from open_tree(..., OPEN_TREE_CLONE) can be dissolved on fput while open_by_handle_at() is between those checks, and umount_tree() can clear mount->mnt_ns. If the helper observes NULL, it dereferences mnt_ns->user_ns and panics. Return false when the RCU read observes a detached mount. This keeps the relaxed permission path conservative: a mount no longer attached to a namespace cannot authorize open_by_handle_at() access.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-72034 records a Unknown severity vulnerability in fhandle: reject detached mounts in capable_wrt_mount(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=620c266f394932e5decc4b34683a75dfc59dc2f4 <15104234c267ebe04b9f9a73e5c2179cc265ff60 || >=620c266f394932e5decc4b34683a75dfc59dc2f4 <6c52226072a3c61337b1eec1799bb987748884fa || >=620c266f394932e5decc4b34683a75dfc59dc2f4 <6ee183d89261bf1d1cf9f06d80a40dab8f36ee55 || >=620c266f394932e5decc4b34683a75dfc59dc2f4 <6c732471740bc2ac9b0946134f9f551dc75f4369 | 15104234c267ebe04b9f9a73e5c2179cc265ff60, 6c52226072a3c61337b1eec1799bb987748884fa, 6ee183d89261bf1d1cf9f06d80a40dab8f36ee55, 6c732471740bc2ac9b0946134f9f551dc75f4369 |
| Linux/Linuxgeneric | 6.11 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: fhandle: reject detached mounts in capable_wrt_mount() The recent fhandle RCU fix moved the mount namespace capability check into capable_wrt_mount(), so a non-NULL mnt_namespace survives the ns_capable() dereference. The helper still assumes the later READ_ONCE(mount->mnt_ns) must be non-NULL because may_decode_fh() checked is_mounted() first. That assumption is not stable. A detached mount from open_tree(..., OPEN_TREE_CLONE) can be dissolved on fput while open_by_handle_at() is between those checks, and umount_tree() can clear mount->mnt_ns. If the helper observes NULL, it dereferences mnt_ns->user_ns and panics. Return false when the RCU read observes a detached mount. This keeps the relaxed permission path conservative: a mount no longer attached to a namespace cannot authorize open_by_handle_at() access.
Quoted source text, attributed separately from HOL analysis.