Impact
The vulnerability exists in the mtdoops kernel module. When the backing MTD device is removed, the module fails to free the page bitmap it allocated during registration. If the device is later re‑registered, a new bitmap is allocated and the old pointer is overwritten, leaving the original memory unfreed. Repeating removal and re‑registration cycles leaks one vmalloc allocation each time, which can eventually exhaust available memory, causing a denial of service.
Affected Systems
All Linux kernel releases that include the mtdoops module and support removable MTD devices are affected. No specific version numbers are listed, so any kernel version built with this module should be considered potentially vulnerable.
Risk and Exploitability
It is inferred that the attacker would need root or system‑level privileges to load the mtdoops module and manipulate MTD devices. The EPSS score is less than 1%, indicating a very low predicted exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation would most likely require the ability to register and deregister a removable MTD device repeatedly while the mtdoops module remains loaded, potentially leading to memory exhaustion and a denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA