A vulnerability categorized as critical has been discovered in Linux Kernel up to 7.2-rc2. Affected by this issue is the function __reserve_metadata_snap/__release_metadata_snap of the component dm thin metadata. The manipulation results in improper update of reference count.

This vulnerability was named CVE-2026-72108. The attack needs to be approached locally. There is no available exploit.

It is advisable to upgrade the affected component.