CVE-2026-93049
In the Linux kernel, the following vulnerability has been resolved:
mtd: mtdswap: Avoid freeing registered blktrans device twice
In mtdswap_add_mtd(), debugfs setup failure after successful blktrans registration can free mbd_dev twice.
add_mtd_blktrans_dev() initializes the blktrans device reference and publishes the disk. Once that succeeds, del_mtd_blktrans_dev() tears the disk down and drops the blktrans reference; when that reference reaches zero, blktrans_dev_release() frees the mtd_blktrans_dev.
The debugfs failure path called del_mtd_blktrans_dev(mbd_dev), then fell through the common cleanup label and called kfree(mbd_dev) again.
Leer descripción completaMostrar menos
Clear the local pointer after deregistration so the common cleanup can still release the mtdswap state without freeing the blktrans object twice.
This issue was found by a static analysis checker and confirmed by manual source review.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0ce48c6ddea1a8e675a2eb0221b62a9950788f3c
- https://git.kernel.org/stable/c/37be7bc2c2d09c18e939da20224405864a0090b9
- https://git.kernel.org/stable/c/5c349c533e72af2313c3be0f80a24d7407fa4777
- https://git.kernel.org/stable/c/779aa4c66a96bf43d2d62982ea1a9096a9128d87
- https://git.kernel.org/stable/c/a82d93fcfdfd26af17049c34319dfdd079cd1901
- https://git.kernel.org/stable/c/d5086911d532b82ca070d944aa08ddde00baefe4
- https://git.kernel.org/stable/c/ecadb9137aeaa0615183f8d23eabea2b45c862f1
- https://git.kernel.org/stable/c/eec130fc9ffbbd08a5d5432683122b79aca2a726
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93049",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e8e3edb95ce6a146bc774b6cfad3553f4383edc8",
"lessThan": "ecadb9137aeaa0615183f8d23eabea2b45c862f1",
"versionType": "git"
},
{
"status": "affected",
"version": "e8e3edb95ce6a146bc774b6cfad3553f4383edc8",
"lessThan": "eec130fc9ffbbd08a5d5432683122b79aca2a726",
"versionType": "git"
},
{
"status": "affected",
"version": "e8e3edb95ce6a146bc774b6cfad3553f4383edc8",
"lessThan": "d5086911d532b82ca070d944aa08ddde00baefe4",
"versionType": "git"
},
{
"status": "affected",
"version": "e8e3edb95ce6a146bc774b6cfad3553f4383edc8",
"lessThan": "0ce48c6ddea1a8e675a2eb0221b62a9950788f3c",
"versionType": "git"
},
{
"status": "affected",
"version": "e8e3edb95ce6a146bc774b6cfad3553f4383edc8",
"lessThan": "a82d93fcfdfd26af17049c34319dfdd079cd1901",
"versionType": "git"
},
{
"status": "affected",
"version": "e8e3edb95ce6a146bc774b6cfad3553f4383edc8",
"lessThan": "5c349c533e72af2313c3be0f80a24d7407fa4777",
"versionType": "git"
},
{
"status": "affected",
"version": "e8e3edb95ce6a146bc774b6cfad3553f4383edc8",
"lessThan": "37be7bc2c2d09c18e939da20224405864a0090b9",
"versionType": "git"
},
{
"status": "affected",
"version": "e8e3edb95ce6a146bc774b6cfad3553f4383edc8",
"lessThan": "779aa4c66a96bf43d2d62982ea1a9096a9128d87",
"versionType": "git"
}
],
"programFiles": [
"drivers/mtd/mtdswap.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.14",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/mtd/mtdswap.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:58.223",
"references": [
{
"url": "https://git.kernel.org/stable/c/0ce48c6ddea1a8e675a2eb0221b62a9950788f3c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/37be7bc2c2d09c18e939da20224405864a0090b9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5c349c533e72af2313c3be0f80a24d7407fa4777",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/779aa4c66a96bf43d2d62982ea1a9096a9128d87",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a82d93fcfdfd26af17049c34319dfdd079cd1901",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d5086911d532b82ca070d944aa08ddde00baefe4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ecadb9137aeaa0615183f8d23eabea2b45c862f1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/eec130fc9ffbbd08a5d5432683122b79aca2a726",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: mtdswap: Avoid freeing registered blktrans device twice\n\nIn mtdswap_add_mtd(), debugfs setup failure after successful blktrans\nregistration can free mbd_dev twice.\n\nadd_mtd_blktrans_dev() initializes the blktrans device reference and\npublishes the disk. Once that succeeds, del_mtd_blktrans_dev() tears the\ndisk down and drops the blktrans reference; when that reference reaches\nzero, blktrans_dev_release() frees the mtd_blktrans_dev.\n\nThe debugfs failure path called del_mtd_blktrans_dev(mbd_dev), then fell\nthrough the common cleanup label and called kfree(mbd_dev) again. Clear\nthe local pointer after deregistration so the common cleanup can still\nrelease the mtdswap state without freeing the blktrans object twice.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review."
}
],
"lastModified": "2026-09-17T17:17:58.223",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}