Description
In the Linux kernel, the following vulnerability has been resolved:

mtd: mtdoops: free page bitmap when the backing MTD is removed

mtdoops_notify_add() allocates oops_page_used when the configured MTD
device is registered. mtdoops_notify_remove() detaches from that device
but leaves the bitmap allocated. If the same MTD device is later
registered again, the add path allocates a new bitmap and overwrites the
old pointer, leaking one vmalloc allocation per remove/add cycle.

This is only visible when the backing MTD device can disappear and be
registered again while mtdoops remains loaded, so the usual static MTD
case does not expose it.

Free the bitmap after unregistering the dumper and flushing the pending
workers, then clear the pointer and page count before a later attach can
allocate fresh state. Clearing the pointer also keeps the module exit
path from freeing the same bitmap a second time after a remove event.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion (Memory Leak)
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in the mtdoops kernel module. When the backing MTD device is removed, the module fails to free the page bitmap it allocated during registration. If the device is later re‑registered, a new bitmap is allocated and the old pointer is overwritten, leaving the original memory unfreed. Repeating removal and re‑registration cycles leaks one vmalloc allocation each time, which can eventually exhaust available memory, causing a denial of service.

Affected Systems

All Linux kernel releases that include the mtdoops module and support removable MTD devices are affected. No specific version numbers are listed, so any kernel version built with this module should be considered potentially vulnerable.

Risk and Exploitability

It is inferred that the attacker would need root or system‑level privileges to load the mtdoops module and manipulate MTD devices. The EPSS score is less than 1%, indicating a very low predicted exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation would most likely require the ability to register and deregister a removable MTD device repeatedly while the mtdoops module remains loaded, potentially leading to memory exhaustion and a denial of service.

Generated by OpenCVE AI on September 18, 2026 at 07:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel release that incorporates the fix for the mtdoops bitmap memory leak.
  • If updating is not immediately possible, disable the mtdoops kernel module or use a kernel configuration that does not load it for removable MTD devices.
  • Restrict root or privileged access to prevent untrusted users from repeatedly registering and removing MTD devices while mtdoops is loaded.

Generated by OpenCVE AI on September 18, 2026 at 07:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mtd: mtdoops: free page bitmap when the backing MTD is removed mtdoops_notify_add() allocates oops_page_used when the configured MTD device is registered. mtdoops_notify_remove() detaches from that device but leaves the bitmap allocated. If the same MTD device is later registered again, the add path allocates a new bitmap and overwrites the old pointer, leaking one vmalloc allocation per remove/add cycle. This is only visible when the backing MTD device can disappear and be registered again while mtdoops remains loaded, so the usual static MTD case does not expose it. Free the bitmap after unregistering the dumper and flushing the pending workers, then clear the pointer and page count before a later attach can allocate fresh state. Clearing the pointer also keeps the module exit path from freeing the same bitmap a second time after a remove event.
Title mtd: mtdoops: free page bitmap when the backing MTD is removed
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:37.676Z

Reserved: 2026-09-11T19:38:34.777Z

Link: CVE-2026-89953

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:05.530

Modified: 2026-09-16T11:17:05.530

Link: CVE-2026-89953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:12:41Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime