SB2026091713 - Memory leak in Linux kernel mtd driver



SB2026091713 - Memory leak in Linux kernel mtd driver

Published: September 17, 2026

Security Bulletin ID SB2026091713
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Partial DoS

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Memory leak (CVE-ID: CVE-2026-89953)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a memory leak in the mtdoops notification removal handler when a configured backing MTD device is removed and registered again while mtdoops remains loaded. A local privileged user can repeatedly remove and register the configured backing MTD device to exhaust vmalloc memory.

The issue is only exposed when the backing MTD device can disappear and later be registered again; typical static MTD configurations do not expose it.


Remediation

Install update from vendor's website.