CVE-2026-72171
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
mtd: slram: remove failed entries from the device list
register_device() links a new slram_mtdlist entry before allocating all of the state needed by the entry. If a later allocation, memremap(), or mtd_device_register() fails, the partially initialized entry remains on the global list. A later cleanup can then dereference or free invalid state from that failed entry.
Unwind the partially initialized entry and clear the list tail on each failure path after the entry has been linked.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9ee674ab10f755bbedbcbb8e76745d2bb8de88d1 | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e97415b8254d9cc131b7bb1c80fcf38123269b9a | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f40acf577bb0fb0829f285ecfeb27d817840601c | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 200b8bc5b6065b02f3775cf131f14b8e1156a00a | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2fd0cbbb34447ccddab67a2a638a07c6d94cae7a | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d8dcbbfa0d695a5244059aa34a2e81f3e8df1082 | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < bdcdfc2464659789032edfad15ff5f7a166f5d7b | affected |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 36f1648644d769c496a8e47e53603e863e358d73 | affected |
| Linux | Linux | 2.6.12 | affected |
| Linux | Linux | 0 < 2.6.12 | unaffected |
| Linux | Linux | 5.10.261 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.212 <= 5.15.* | unaffected |
| Linux | Linux | 6.1.178 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.145 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.97 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.40 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/9ee674ab10f755bbedbcbb8e76745d2bb8de88d1
- https://git.kernel.org/stable/c/e97415b8254d9cc131b7bb1c80fcf38123269b9a
- https://git.kernel.org/stable/c/f40acf577bb0fb0829f285ecfeb27d817840601c
- https://git.kernel.org/stable/c/200b8bc5b6065b02f3775cf131f14b8e1156a00a
- https://git.kernel.org/stable/c/2fd0cbbb34447ccddab67a2a638a07c6d94cae7a
- https://git.kernel.org/stable/c/d8dcbbfa0d695a5244059aa34a2e81f3e8df1082
- https://git.kernel.org/stable/c/bdcdfc2464659789032edfad15ff5f7a166f5d7b
- https://git.kernel.org/stable/c/36f1648644d769c496a8e47e53603e863e358d73
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.