Impact
This bug occurs in the null_blk block‑device driver when a zoned device is powered off; the kernel allocates an array of zones in null_init_zoned_dev() but never frees that memory in null_del_dev(). Each power cycle allocates a new array and the previous one is never reclaimed. Over time the leaked memory can grow until system resources are exhausted, potentially leading to a denial‑of‑service condition. The weakness is a classic memory‑leak vulnerability (CWE‑401). It does not directly compromise confidentiality or integrity, but repeated use of the affected driver can degrade overall system stability.
Affected Systems
The flaw resides in the Linux kernel’s null_blk driver. The affected products are any Linux kernel that includes null_blk, the test data does not provide a specific kernel version, but any system that enables the null_blk subsystem with zoned devices is potentially impacted.
Risk and Exploitability
The exploit probability reported by EPSS is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of widespread exploitation. However, the attack vector requires local system control to repeatedly power the device on and off, which is plausible for an attacker with physical or privileged access. The potential denial‑of‑service impact makes this a moderate risk for environments that rely heavily on null_blk zoned devices.
OpenCVE Enrichment
Debian DLA
Debian DSA