DEBIAN-CVE-2026-72220
In the Linux kernel, the following vulnerability has been resolved: sunrpc: harden rqprocinfo lifecycle to prevent double-free The svcreleaserqst() function executes the callback inside rqstp->rqprocinfo->pcrelease. However, if a worker thread begins processing a new request and encounters an early error path (e.g., unsupported protocol, short frame, or bad auth) before a valid rqprocinfo is installed, a stale release hook can be re-triggered against reused state from the previous RPC, resulting in a double-free or use-after-free vulnerability. Harden the lifecycle of rqprocinfo by: 1. Ensuring svcreleaserqst() always clears rqprocinfo after the optional pcrelease() call, regardless of whether the hook exists. 2. Explicitly clearing rqprocinfo at request entry in svcprocess() before any early decode or drop paths. 3. Ensuring svcprocessbc() does the same at backchannel entry. This guarantees that error flows will not encounter a non-NULL stale rqprocinfo pointer when there is nothing to release.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-72220