Memory Leak Vulnerability in Linux Kernel by Vendor
CVE-2026-46221

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-46221?

A memory leak vulnerability exists in the Linux Kernel's EDAC/versalnet subsystem where allocated device names are not properly freed during normal removal processes. The device name, initially allocated using kzalloc(), is assigned to dev->init_name and subsequently becomes unreachable due to device_register() operations. To resolve this issue, it is recommended to use a stack-local character array instead of relying on dynamic memory allocation, preventing memory leakage and optimizing resource management.

Affected Version(s)

Linux d5fe2fec6c40dda03df8cc9b4a97de0b7e39f984 < 24d2912962d087ebff7c4984f8ac34a5f23c8dbf

Linux d5fe2fec6c40dda03df8cc9b4a97de0b7e39f984

Linux d5fe2fec6c40dda03df8cc9b4a97de0b7e39f984 < 8cf5dd235eff6008cb04c3d8064d2acfa90616f1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.