-

CVE-2026-93049

mtd: mtdswap: Avoid freeing registered blktrans device twice

In the Linux kernel, the following vulnerability has been resolved:

mtd: mtdswap: Avoid freeing registered blktrans device twice

In mtdswap_add_mtd(), debugfs setup failure after successful blktrans
registration can free mbd_dev twice.

add_mtd_blktrans_dev() initializes the blktrans device reference and
publishes the disk. Once that succeeds, del_mtd_blktrans_dev() tears the
disk down and drops the blktrans reference; when that reference reaches
zero, blktrans_dev_release() frees the mtd_blktrans_dev.

The debugfs failure path called del_mtd_blktrans_dev(mbd_dev), then fell
through the common cleanup label and called kfree(mbd_dev) again. Clear
the local pointer after deregistration so the common cleanup can still
release the mtdswap state without freeing the blktrans object twice.

This issue was found by a static analysis checker and confirmed by
manual source review.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e8e3edb95ce6a146bc774b6cfad3553f4383edc8
Version < ecadb9137aeaa0615183f8d23eabea2b45c862f1
Status affected
Version e8e3edb95ce6a146bc774b6cfad3553f4383edc8
Version < eec130fc9ffbbd08a5d5432683122b79aca2a726
Status affected
Version e8e3edb95ce6a146bc774b6cfad3553f4383edc8
Version < d5086911d532b82ca070d944aa08ddde00baefe4
Status affected
Version e8e3edb95ce6a146bc774b6cfad3553f4383edc8
Version < 0ce48c6ddea1a8e675a2eb0221b62a9950788f3c
Status affected
Version e8e3edb95ce6a146bc774b6cfad3553f4383edc8
Version < a82d93fcfdfd26af17049c34319dfdd079cd1901
Status affected
Version e8e3edb95ce6a146bc774b6cfad3553f4383edc8
Version < 5c349c533e72af2313c3be0f80a24d7407fa4777
Status affected
Version e8e3edb95ce6a146bc774b6cfad3553f4383edc8
Version < 37be7bc2c2d09c18e939da20224405864a0090b9
Status affected
Version e8e3edb95ce6a146bc774b6cfad3553f4383edc8
Version < 779aa4c66a96bf43d2d62982ea1a9096a9128d87
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.14
Status affected
Version 0
Version < 4.14
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.116
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ecadb9137aeaa0615183f8d23eabea2b45c862f1
https://git.kernel.org/stable/c/eec130fc9ffbbd08a5d5432683122b79aca2a726
https://git.kernel.org/stable/c/d5086911d532b82ca070d944aa08ddde00baefe4
https://git.kernel.org/stable/c/0ce48c6ddea1a8e675a2eb0221b62a9950788f3c
https://git.kernel.org/stable/c/a82d93fcfdfd26af17049c34319dfdd079cd1901
https://git.kernel.org/stable/c/5c349c533e72af2313c3be0f80a24d7407fa4777
https://git.kernel.org/stable/c/37be7bc2c2d09c18e939da20224405864a0090b9
https://git.kernel.org/stable/c/779aa4c66a96bf43d2d62982ea1a9096a9128d87