EDAC/versalnet: Fix device name memory leak
Summary
| CVE | CVE-2026-46221 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-28 10:16:37 UTC |
| Updated | 2026-05-28 13:44:01 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
EDAC/versalnet: Fix device name memory leak
The device name allocated via kzalloc() in init_one_mc() is assigned to
dev->init_name but never freed on the normal removal path. device_register()
copies init_name and then sets dev->init_name to NULL, so the name pointer
becomes unreachable from the device. Thus leaking memory.
Use a stack-local char array instead of using kzalloc() for name. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected d5fe2fec6c40dda03df8cc9b4a97de0b7e39f984 24d2912962d087ebff7c4984f8ac34a5f23c8dbf git |
Not specified |
| CNA |
Linux |
Linux |
affected d5fe2fec6c40dda03df8cc9b4a97de0b7e39f984 b16033c8774f5fb4c0cb9b445a1dfc68f499ae6a git |
Not specified |
| CNA |
Linux |
Linux |
affected d5fe2fec6c40dda03df8cc9b4a97de0b7e39f984 8cf5dd235eff6008cb04c3d8064d2acfa90616f1 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.18 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.32 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0.9 7.0.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1-rc3 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/24d2912962d087ebff7c4984f8ac34a5f23c8dbf |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8cf5dd235eff6008cb04c3d8064d2acfa90616f1 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b16033c8774f5fb4c0cb9b445a1dfc68f499ae6a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.