Impact
The flaw arises when the kernel attempts to add a mock IOMMU device and the subsequent device_add call fails. In that error path the firmware specification is freed, but the outer IOMMU structure allocated by dev_iommu_get() is not released. This leaves an orphaned memory allocation that kmemleak detects as a memory leak. Repeated failures can accumulate unreleased kernel objects, gradually consuming kernel memory and potentially destabilizing the system. The weakness is a classic case of an unreleased resource (CWE-772).
Affected Systems
Any Linux kernel that contains the iommu_mock_device_add routine and exposes the IOMMU mock interface is affected. Systems that compile with IOMMU mock support and allow the self‑test ioctl or any application that triggers a device_add on a mock adapter are at risk. The advisory does not list specific kernel versions, so any installationpatch code path.
Risk and Exploitability
A CVSS score of 5.5 indicates moderate severity, and an EPSS score of less than 1% indicates a very low likelihood of active exploitation. The vulnerability is not currently listed in the CISA KEV catalog. The attack vector is inferred to be a privileged local ioctl; an adversary with sufficient local privileges could repeatedly trigger the failure path, accumulate kernel memory usage, and potentially drive the system into a denial‑of‑service state. Because the flaw requires kernel code execution, it is unlikely to be widely exploitable without elevated access.
OpenCVE Enrichment