SB20260816353 - Incomplete cleanup in Linux kernel mtd devices driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incomplete cleanup (CVE-ID: CVE-2026-72171)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper cleanup in register_device() in the slram driver when handling device registration failures. A local user can trigger allocation or registration failures to cause a denial of service.
The issue occurs after a partially initialized entry has already been linked into the global device list, and a later cleanup can dereference or free invalid state from that failed entry.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/200b8bc5b6065b02f3775cf131f14b8e1156a00a
- https://git.kernel.org/stable/c/2fd0cbbb34447ccddab67a2a638a07c6d94cae7a
- https://git.kernel.org/stable/c/36f1648644d769c496a8e47e53603e863e358d73
- https://git.kernel.org/stable/c/9ee674ab10f755bbedbcbb8e76745d2bb8de88d1
- https://git.kernel.org/stable/c/bdcdfc2464659789032edfad15ff5f7a166f5d7b
- https://git.kernel.org/stable/c/d8dcbbfa0d695a5244059aa34a2e81f3e8df1082
- https://git.kernel.org/stable/c/e97415b8254d9cc131b7bb1c80fcf38123269b9a
- https://git.kernel.org/stable/c/f40acf577bb0fb0829f285ecfeb27d817840601c