CVE-2026-23038 | Linux Kernel up to 6.6.121/6.12.66/6.18.6/6.19-rc5 flexfiles nfs4_ff_alloc_deviceid_node memory leak (EUVD-2026-5056 / Nessus ID 297467)
A vulnerability was found in Linux Kernel up to 6.6.121/6.12.66/6.18.6/6.19-rc5. It has been declared as critical. Affected by this issue is the function nfs4_ff_alloc_deviceid_node of the component flexfiles. The manipulation results in memory leak.
This vulnerability was named CVE-2026-23038. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.