Memory leak in Linux kernel - CVE-2026-89953
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to a memory leak in the mtdoops notification removal handler when a configured backing MTD device is removed and registered again while mtdoops remains loaded. A local privileged user can repeatedly remove and register the configured backing MTD device to exhaust vmalloc memory.
The issue is only exposed when the backing MTD device can disappear and later be registered again; typical static MTD configurations do not expose it.
Affected software
How to mitigate CVE-2026-89953
External References
- https://git.kernel.org/stable/c/1e5cd8bc902331ff801df88cbb299029ae062753
- https://git.kernel.org/stable/c/477d61d54e097e90f748aa18d013805abd56bcbd
- https://git.kernel.org/stable/c/698944132083d143ef965c0090ee14ba1d9e1a5f
- https://git.kernel.org/stable/c/8414f0e9f707226de20b48c7048179fd86d352fc
- https://git.kernel.org/stable/c/956e7da12c114f13c63d126ab1d79c3b6a819060
- https://git.kernel.org/stable/c/a91ac71e67c3e01ed9afd9841435bebb930293f8
- https://git.kernel.org/stable/c/d06f91a52af11630c9f7e487f6daf242ac310cb8
- https://git.kernel.org/stable/c/f25c804947e0a28c15e73da8e2e0db959cbed716