Memory leak in Linux kernel - CVE-2026-45921
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a memory leak in mtd_parser_tplink_safeloader_parse() when parsing TP-Link safeloader partition tables. A local user can trigger an allocation failure for parts[idx].name to cause a denial of service.
The issue was identified through static analysis and code review.
How to mitigate CVE-2026-45921
Sources
- https://git.kernel.org/stable/c/0f5e62ea5c43146eacdc6861cb1022ffae1b79bc
- https://git.kernel.org/stable/c/971e9c53aed82f17a9c6a65daa4e21cc15eba5b1
- https://git.kernel.org/stable/c/980ce2b02dd06a4fdf5fee38b2e14becf9cf7b8b
- https://git.kernel.org/stable/c/e97f5fac8ce9a6b9ec724c97d86b0985e915fdca
- https://git.kernel.org/stable/c/ec121ad626c319085f6d40a52cd04e99b4554926