drivers/base/memory: fix memory block reference leak in poison accounting

Summary

CVECVE-2026-64182
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-19 16:18:00 UTC
Updated2026-07-19 16:18:00 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: drivers/base/memory: fix memory block reference leak in poison accounting memblk_nr_poison_inc() and memblk_nr_poison_sub() look up a memory block via find_memory_block_by_id(), which acquires a reference to the memory block device. Both helpers use the returned memory block without dropping that reference, leaking the device reference on each successful lookup. Drop the reference after updating nr_hwpoison.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 5033091de814ab4b5623faed2755f3064e19e2d2 686b4283f82cd630fafd7ca9b03dfc080b3ec8fa git Not specified
CNA Linux Linux affected 5033091de814ab4b5623faed2755f3064e19e2d2 ce60d9452a0f2effa72fd20ea270c59ca691d455 git Not specified
CNA Linux Linux affected 5033091de814ab4b5623faed2755f3064e19e2d2 24840b3139d7415144b81e4f9f4c44670d15bed9 git Not specified
CNA Linux Linux affected 5033091de814ab4b5623faed2755f3064e19e2d2 8502e2c2d0633f99d94d22ae8dabc10caae1fc2a git Not specified
CNA Linux Linux affected 5033091de814ab4b5623faed2755f3064e19e2d2 03a2cc1756a0570f887d624cd6c535ea0cbd4951 git Not specified
CNA Linux Linux affected 6.2 Not specified
CNA Linux Linux unaffected 6.2 semver Not specified
CNA Linux Linux unaffected 6.6.142 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.92 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.34 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.11 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/8502e2c2d0633f99d94d22ae8dabc10caae1fc2a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/03a2cc1756a0570f887d624cd6c535ea0cbd4951 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/24840b3139d7415144b81e4f9f4c44670d15bed9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/686b4283f82cd630fafd7ca9b03dfc080b3ec8fa 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ce60d9452a0f2effa72fd20ea270c59ca691d455 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report