CVE-2026-72223

medium

Description

In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: Free arena sub-allocations on discover_arenas() error path Memory allocated by btt_freelist_init(), btt_rtt_init(), and btt_maplocks_init() is not freed on some discover_arenas() error paths. This leaks memory when arena discovery fails. Add the missing kfree() calls to release the allocations before returning an error. [ as: commit message and log edits ]

References

https://git.kernel.org/stable/c/eeb95774bc79268e2b78ebf01d8781560b5bd671

https://git.kernel.org/stable/c/ba59b96d8d21dc8729fca44a022ca5919c1848c9

https://git.kernel.org/stable/c/873ced7f345e99f7ee16f9ff226515580332ecc4

https://git.kernel.org/stable/c/7563f69caa9143a491d5f26e563255c734751545

https://git.kernel.org/stable/c/30d490bb2c4cd220e7dedf862ab6a09eb5dcbad5

https://git.kernel.org/stable/c/2d0364937550a7b3e2592629c2a68753ac020b28

https://git.kernel.org/stable/c/13fe4cd9ddd0aacb7777812328be525a11ea3fea

https://git.kernel.org/stable/c/0b0d9404951aacc9717aa61e77af4a6e9e8f8249

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-17

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.0022