CVE-2025-68348 — Missing Release of Resource after Effective Lifetime in Linux
Severity
7.2HIGHOSV
No vectorEPSS
0.0%
top 92.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 24
Latest updateApr 6
Description
In the Linux kernel, the following vulnerability has been resolved:
block: fix memory leak in __blkdev_issue_zero_pages
Move the fatal signal check before bio_alloc() to prevent a memory
leak when BLKDEV_ZERO_KILLABLE is set and a fatal signal is pending.
Previously, the bio was allocated before checking for a fatal signal.
If a signal was pending, the code would break out of the loop without
freeing or chaining the just-allocated bio, causing a memory leak.
This matches the pattern already …
Affected Packages5 packages
▶CVEListV5linux/linuxbf86bcdb40123ee99669ee91b67e023669433a1a — 453e4b0c84d0db1454ff0adf655d91179e6fca3a+4