PT-2026-5535 · Linux+2 · Linux Kernel+2
CVE-2026-23032
·
Published
2026-01-01
·
Updated
2026-08-21
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains an issue where references to fault configfs items are not released when a nullbX device is removed, leading to a kernel memory leak (kmemleak). This occurs when the
CONFIG BLK DEV NULL BLK FAULT INJECTION configuration option is enabled. The issue involves the timeout inject, requeue inject, and init hctx fault inject configfs items created as children of the nullbX configfs group. The fix involves explicitly releasing these references when the reference to the top-level nullbX configfs group is dropped.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu