cbcvebase.
CVE-2026-23032
published 2026-01-31

CVE-2026-23032: In the Linux kernel, the following vulnerability has been resolved: null_blk: fix kmemleak by releasing references to fault configfs items When…

PriorityP421high7.8
EPSS
0.21%
10.9th percentile
In the Linux kernel, the following vulnerability has been resolved: null_blk: fix kmemleak by releasing references to fault configfs items When CONFIG_BLK_DEV_NULL_BLK_FAULT_INJECTION is enabled, the null-blk driver sets up fault injection support by creating the timeout_inject, requeue_inject, and init_hctx_fault_inject configfs items as children of the top-level nullbX configfs group. However, when the nullbX device is removed, the references taken to these fault-config configfs items are not released. As a result, kmemleak reports a memory leak, for example: unreferenced object 0xc00000021ff25c40 (size 32): comm "mkdir", pid 10665, jiffies 4322121578 hex dump (first 32 bytes): 69 6e 69 74 5f 68 63 74 78 5f 66 61 75 6c 74 5f init_hctx_fault_ 69 6e 6a 65 63 74 00 88 00 00 00 00 00 00 00 00 inject.......... backtrace (crc 1a018c86): __kmalloc_node_track_caller_noprof+0x494/0xbd8 kvasprintf+0x74/0xf4 config_item_set_name+0xf0/0x104 config_group_init_type_name+0x48/0xfc fault_config_init+0x48/0xf0 0xc0080000180559e4 configfs_mkdir+0x304/0x814 vfs_mkdir+0x49c/0x604 do_mkdirat+0x314/0x3d0 sys_mkdir+0xa0/0xd8 system_call_exception+0x1b0/0x4f0 system_call_vectored_common+0x15c/0x2ec Fix this by explicitly releasing the references to the fault-config configfs items when dropping the reference to the top-level nullbX configfs group.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.8-1 (forky)linux 6.18.8-1 (forky)
linuxlinux
linuxlinux>= bb4c19e030f45c5416f1eb4daa94fbaf7165e9ea < 1a3286edf4d48ce37f8982ff3c3b65159a5ecbb21a3286edf4d48ce37f8982ff3c3b65159a5ecbb2
linuxlinux>= bb4c19e030f45c5416f1eb4daa94fbaf7165e9ea < d59ba448ccd595d5d65e197216cf781a87db2b28d59ba448ccd595d5d65e197216cf781a87db2b28
linuxlinux>= bb4c19e030f45c5416f1eb4daa94fbaf7165e9ea < f1718da051282698aa8fa150bebb9724f6389fdaf1718da051282698aa8fa150bebb9724f6389fda
linuxlinux>= bb4c19e030f45c5416f1eb4daa94fbaf7165e9ea < 40b94ec7edbbb867c4e26a1a43d2b898f04b93c540b94ec7edbbb867c4e26a1a43d2b898f04b93c5
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 6.13.0 < 6.18.76.18.7
linuxlinux_kernel>= 6.4.0 < 6.6.1226.6.122
linuxlinux_kernel>= 6.7.0 < 6.12.676.12.67
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8
ubuntulinux-azure-fde-6.17
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.17
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop

CVSS provenance

vendor_ubuntu7.8HIGH
vendor_redhat4.4LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.