Memory leak in Linux kernel - CVE-2026-45948
Published: May 28, 2026
Vulnerability identifier: #VU132537
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-45948
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a memory leak in ext4_ext_shift_extents() when shifting extents. A local user can trigger the vulnerable code path to cause a denial of service.
How to mitigate CVE-2026-45948
Install security update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/12615ab4bfb69678e5d961b28bb70040299e51b1
- https://git.kernel.org/stable/c/1bce219ee5512cf179ba40cf114945a14a16e21f
- https://git.kernel.org/stable/c/2f4b1052246ca646bb17bfe0f53df2fdf9729b58
- https://git.kernel.org/stable/c/4a79fde8db7eba7f1128d971ceba4e3c9ac84aec
- https://git.kernel.org/stable/c/7e807cb8603b7664fa630a696cd891d9a03c248d
- https://git.kernel.org/stable/c/afc5e61e1a07b2b833bd72cbee36ecce9cd901e2
- https://git.kernel.org/stable/c/bd7b52557e4a3ccd7595fdb3a585f1257de57935
- https://git.kernel.org/stable/c/ca81109d4a8f192dc1cbad4a1ee25246363c2833