cve-2026-46040

MEDIUM CVSS 5.5 nvd
Description

In the Linux kernel, the following vulnerability has been resolved: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails When fsnotify_add_inode_mark_locked() fails in inotify_new_watch(), the error path calls inotify_remove_from_idr() but does not call dec_inotify_watches() to undo the preceding inc_inotify_watches(). This leaks a watch count, and repeated failures can exhaust the max_user_watches limit with -ENOSPC even when no watches are active. Prior to commit 1cce1eea0aff ("inotify: Convert to using per-namespace limits"), the watch count was incremented after fsnotify_add_mark_locked() succeeded, so this path was not affected. The conversion moved inc_inotify_watches() before the mark insertion without adding the corresponding rollback. Add the missing dec_inotify_watches() call in the error path.

Timeline
Published
2026-05-27
Last Modified
2026-09-08
CVSS Details
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
Affected Products
  • linux linux_kernel
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H 1.8 3.6 nvd@nist.gov
CPE configurations
OR
CPE Version range Vulnerable
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 4.11, < 5.10.258 yes
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 5.11, < 5.15.209 yes
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 5.16, < 6.1.175 yes
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.2, < 6.6.140 yes
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.7, < 6.12.86 yes
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.13, < 6.18.27 yes
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.19, < 7.0.4 yes
NVD metadata
NVD status
Modified
Source identifier
416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
Linked Vulnerabilities

{
  "cvss": 5.5,
  "datePublished": "2026-05-27T14:17:23.387",
  "dateUpdated": "2026-09-08T09:18:07.063",
  "description": "In the Linux kernel, the following vulnerability has been resolved:\n\ninotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails\n\nWhen fsnotify_add_inode_mark_locked() fails in inotify_new_watch(),\nthe error path calls inotify_remove_from_idr() but does not call\ndec_inotify_watches() to undo the preceding inc_inotify_watches().\nThis leaks a watch count, and repeated failures can exhaust the\nmax_user_watches limit with -ENOSPC even when no watches are active.\n\nPrior to commit 1cce1eea0aff (\"inotify: Convert to using per-namespace\nlimits\"), the watch count was incremented after fsnotify_add_mark_locked()\nsucceeded, so this path was not affected. The conversion moved\ninc_inotify_watches() before the mark insertion without adding the\ncorresponding rollback.\n\nAdd the missing dec_inotify_watches() call in the error path.",
  "id": "CVE-2026-46040",
  "raw": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "fs/notify/inotify/inotify_user.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "3ab58cf42c46bf2366d2f55ae5c59299d5e178b7",
                "status": "affected",
                "version": "1cce1eea0aff51201753fcaca421df825b0813b6",
                "versionType": "git"
              },
              {
                "lessThan": "10edf7e0ffdc7faa18e2244b17722c1b882b8273",
                "status": "affected",
                "version": "1cce1eea0aff51201753fcaca421df825b0813b6",
                "versionType": "git"
              },
              {
                "lessThan": "3ad9ccea1b25435f6179b57aa891960beb7ce8f9",
                "status": "affected",
                "version": "1cce1eea0aff51201753fcaca421df825b0813b6",
                "versionType": "git"
              },
              {
                "lessThan": "8bcc1cd237ab5ccfdd102869fa031c541943cf40",
                "status": "affected",
                "version": "1cce1eea0aff51201753fcaca421df825b0813b6",
                "versionType": "git"
              },
              {
                "lessThan": "73ddc8518a32baff6bc17afda4ee1ebae5b4ed12",
                "status": "affected",
                "version": "1cce1eea0aff51201753fcaca421df825b0813b6",
                "versionType": "git"
              },
              {
                "lessThan": "fdaa42ca370d056428e5e171247c8fdce8dff36a",
                "status": "affected",
                "version": "1cce1eea0aff51201753fcaca421df825b0813b6",
                "versionType": "git"
              },
              {
                "lessThan": "9e48844f708eb48bae4e79cb21edc097c966306d",
                "status": "affected",
                "version": "1cce1eea0aff51201753fcaca421df825b0813b6",
                "versionType": "git"
              },
              {
                "lessThan": "6a320935fa4293e9e599ec9f85dc9eb3be7029f8",
                "status": "affected",
                "version": "1cce1eea0aff51201753fcaca421df825b0813b6",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "fs/notify/inotify/inotify_user.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "4.11"
              },
              {
                "lessThan": "4.11",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.258",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.209",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.175",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.140",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.86",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.18.*",
                "status": "unaffected",
                "version": "6.18.27",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.*",
                "status": "unaffected",
                "version": "7.0.4",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      },
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EDD978C9-3435-4AC5-AE97-062846CF653F",
                "versionEndExcluding": "5.10.258",
                "versionStartIncluding": "4.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "919C10A9-7951-4A74-BADD-C135A0A8D8B4",
                "versionEndExcluding": "5.15.209",
                "versionStartIncluding": "5.11",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "92385813-D91D-480D-83A1-F423D2CBB2BA",
                "versionEndExcluding": "6.1.175",
                "versionStartIncluding": "5.16",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A1A92866-F406-43B5-B2D1-CFC274753E9D",
                "versionEndExcluding": "6.6.140",
                "versionStartIncluding": "6.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "55DA1C62-9991-451E-B8A8-E0004E00F789",
                "versionEndExcluding": "6.12.86",
                "versionStartIncluding": "6.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A10AC84F-C058-47D5-85B4-E6E51A613B74",
                "versionEndExcluding": "6.18.27",
                "versionStartIncluding": "6.13",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CDB78D6D-22C3-4154-B0D0-94AF1CE5C2E3",
                "versionEndExcluding": "7.0.4",
                "versionStartIncluding": "6.19",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ninotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails\n\nWhen fsnotify_add_inode_mark_locked() fails in inotify_new_watch(),\nthe error path calls inotify_remove_from_idr() but does not call\ndec_inotify_watches() to undo the preceding inc_inotify_watches().\nThis leaks a watch count, and repeated failures can exhaust the\nmax_user_watches limit with -ENOSPC even when no watches are active.\n\nPrior to commit 1cce1eea0aff (\"inotify: Convert to using per-namespace\nlimits\"), the watch count was incremented after fsnotify_add_mark_locked()\nsucceeded, so this path was not affected. The conversion moved\ninc_inotify_watches() before the mark insertion without adding the\ncorresponding rollback.\n\nAdd the missing dec_inotify_watches() call in the error path."
      }
    ],
    "id": "CVE-2026-46040",
    "lastModified": "2026-09-08T09:18:07.063",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ]
    },
    "published": "2026-05-27T14:17:23.387",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/10edf7e0ffdc7faa18e2244b17722c1b882b8273"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/3ab58cf42c46bf2366d2f55ae5c59299d5e178b7"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/3ad9ccea1b25435f6179b57aa891960beb7ce8f9"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/6a320935fa4293e9e599ec9f85dc9eb3be7029f8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/73ddc8518a32baff6bc17afda4ee1ebae5b4ed12"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/8bcc1cd237ab5ccfdd102869fa031c541943cf40"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/9e48844f708eb48bae4e79cb21edc097c966306d"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "tags": [
          "Patch"
        ],
        "url": "https://git.kernel.org/stable/c/fdaa42ca370d056428e5e171247c8fdce8dff36a"
      },
      {
        "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-Other"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  },
  "severity": "MEDIUM",
  "source": "nvd",
  "title": "In the Linux kernel, the following vulnerability has been resolved:\n\ninotify: fix watch count leak when fsnotify_add_..."
}
View JSON API Download JSON