Description
In the Linux kernel, the following vulnerability has been resolved:

mtd: virt-concat: free duplicate generated name

Every MTD registration runs mtd_virt_concat_create_join(). Once a
virtual concat has already been registered, the function builds the same
name again and takes the equal-name branch. That branch skips to the
next item without freeing the newly allocated string.

Free the temporary name before continuing.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel’s MTD virtual concatenation subsystem generates a device name for each virtual concat registration. If a device with that name already exists, the code mistakenly skips freeing the newly allocated string, causing a memory leak that can grow unbounded with repeated registrations. This flaw does not provide direct code execution nor data disclosure, but it can exhaust kernel memory and lead to a denial‑of‑service condition.

Affected Systems

All Linux kernel builds that include the MTD virtual concat subsystem are vulnerable; the advisory lists the kernel itself without a specific version range, implying that any kernel containing the unpatched mtd/virt‑concat code is affected until the fix is applied.

Risk and Exploitability

The CVSS score of 5.5 classifies the issue as medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a local attacker with the ability to register MTD devices—repeated or sustained registrations would drain kernel memory and potentially crash the system.

Generated by OpenCVE AI on August 18, 2026 at 02:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a kernel release that incorporates the commit which frees the duplicate generated name; install the latest stable kernel from your distribution’s package repository.
  • If an immediate upgrade is not feasible, apply a local patch to the mtd/virt‑concat source that releases the temporary name before proceeding to the next registration item.
  • If the virtual concat feature is not required, disable it in the kernel configuration or unload its module to remove the vulnerable code path.

Generated by OpenCVE AI on August 18, 2026 at 02:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mtd: virt-concat: free duplicate generated name Every MTD registration runs mtd_virt_concat_create_join(). Once a virtual concat has already been registered, the function builds the same name again and takes the equal-name branch. That branch skips to the next item without freeing the newly allocated string. Free the temporary name before continuing.
Title mtd: virt-concat: free duplicate generated name
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:06:10.123Z

Reserved: 2026-07-30T09:28:09.396Z

Link: CVE-2026-68468

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:19:57.520

Modified: 2026-08-17T06:17:56.167

Link: CVE-2026-68468

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-68468 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T02:15:04Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime