CVE-2026-89953
CVE CVE-2026-89953EUVD EUVD-2026-80553Published 2026-09-16T10:32:37.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: mtd: mtdoops: free page bitmap when the backing MTD is removed mtdoops_notify_add() allocates oops_page_used when the configured MTD device is registered. mtdoops_notify_remove() detaches from that device but leaves the bitmap allocated. If the same MTD device is later registered again, the add path allocates a new bitmap and overwrites the old pointer, leaking one vmalloc allocation per remove/add cycle. This is only visible when the backing MTD device can disappear and be registered again while mtdoops remains loaded, so the usual static MTD case does not expose it. Free the bitmap after unregistering the dumper and flushing the pending workers, then clear the pointer and page count before a later attach can allocate fresh state. Clearing the pointer also keeps the module exit path from freeing the same bitmap a second time after a remove event.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 0; patch: 6.6.157; patch: 6.18.51; patch: 7.2.5; be95745f01677245a061a8f51473ef5ec8ad008e <698944132083d143ef965c0090ee14ba1d9e1a5f; be95745f01677245a061a8f51473ef5ec8ad008e <f25c804947e0a28c15e73da8e2e0db959cbed716; patch: 6.12.110; be95745f01677245a061a8f51473ef5ec8ad008e <d06f91a52af11630c9f7e487f6daf242ac310cb8; be95745f01677245a061a8f51473ef5ec8ad008e <477d61d54e097e90f748aa18d013805abd56bcbd; be95745f01677245a061a8f51473ef5ec8ad008e <8414f0e9f707226de20b48c7048179fd86d352fc; patch: 5.10.270; patch: 6.1.188; be95745f01677245a061a8f51473ef5ec8ad008e <a91ac71e67c3e01ed9afd9841435bebb930293f8; patch: 5.15.221; be95745f01677245a061a8f51473ef5ec8ad008e <956e7da12c114f13c63d126ab1d79c3b6a819060; 2.6.33; be95745f01677245a061a8f51473ef5ec8ad008e <1e5cd8bc902331ff801df88cbb299029ae062753; patch: 7.3-rc1
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.