Description
In the Linux kernel, the following vulnerability has been resolved:

mtd: mtdswap: Avoid freeing registered blktrans device twice

In mtdswap_add_mtd(), debugfs setup failure after successful blktrans
registration can free mbd_dev twice.

add_mtd_blktrans_dev() initializes the blktrans device reference and
publishes the disk. Once that succeeds, del_mtd_blktrans_dev() tears the
disk down and drops the blktrans reference; when that reference reaches
zero, blktrans_dev_release() frees the mtd_blktrans_dev.

The debugfs failure path called del_mtd_blktrans_dev(mbd_dev), then fell
through the common cleanup label and called kfree(mbd_dev) again. Clear
the local pointer after deregistration so the common cleanup can still
release the mtdswap state without freeing the blktrans object twice.

This issue was found by a static analysis checker and confirmed by
manual source review.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption / potential privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel bug causes a double free of a blktrans device during the cleanup path of the mtdswap subsystem. The erroneous release path frees the device twice, corrupting the kernel heap. This kernel memory corruption could enable an attacker to execute arbitrary code in privileged mode or crash the system. The flaw corresponds to a double‑free weakness.

Affected Systems

The issue affects Linux kernel implementations that include the mtdswap subsystem and register blktrans devices for debugfs. No version numbers are listed, but any kernel build containing this code path may be susceptible.

Risk and Exploitability

The exploit probability per EPSS is less than 1% and the vulnerability is not in the CISA KEV catalog. The flaw relies on a local scenario where a write failure in mtdswap cleanup triggers the double free, so an adversary with kernel write access could exploit it for elevation of privilege or denial of service. Because the risk is low in most environments, the overall threat rating is moderate unless the vulnerable code path is in active use.

Generated by OpenCVE AI on September 19, 2026 at 06:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the mtdswap double‑free fix.
  • If an update is not feasible, disable or remove the mtdswap module or rebuild the kernel without mtdswap support, and prevent debugfs access to the affected device.
  • Apply configuration hardening: restrict debugfs mount to root‑only and monitor kernel logs for abnormal blktrans de‑registration events.

Generated by OpenCVE AI on September 19, 2026 at 06:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mtd: mtdswap: Avoid freeing registered blktrans device twice In mtdswap_add_mtd(), debugfs setup failure after successful blktrans registration can free mbd_dev twice. add_mtd_blktrans_dev() initializes the blktrans device reference and publishes the disk. Once that succeeds, del_mtd_blktrans_dev() tears the disk down and drops the blktrans reference; when that reference reaches zero, blktrans_dev_release() frees the mtd_blktrans_dev. The debugfs failure path called del_mtd_blktrans_dev(mbd_dev), then fell through the common cleanup label and called kfree(mbd_dev) again. Clear the local pointer after deregistration so the common cleanup can still release the mtdswap state without freeing the blktrans object twice. This issue was found by a static analysis checker and confirmed by manual source review.
Title mtd: mtdswap: Avoid freeing registered blktrans device twice
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:39.679Z

Reserved: 2026-09-17T15:57:05.658Z

Link: CVE-2026-93049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:58.223

Modified: 2026-09-17T17:17:58.223

Link: CVE-2026-93049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:15:04Z

Weaknesses