Executive brief
A vulnerability in the Linux kernel's memory leak detection tool (kmemleak) can cause the entire system to freeze or crash (deadlock). This occurs when the system attempts to log a warning message while already holding a critical internal lock, particularly when network-based logging is enabled. An exploit of this flaw would result in a total loss of system availability, requiring a hard reboot.
Technical details
A lock inversion deadlock exists in mm/kmemleak.c within the mem_pool_alloc() function. When the memory pool is exhausted, the kernel calls pr_warn_once() while holding the kmemleak_lock. If netpoll/netconsole is enabled, this warning triggers a network transmission that calls __alloc_skb(), which in turn calls back into kmemleak code (__create_object) and attempts to reacquire the same kmemleak_lock. This circular dependency results in a kernel deadlock. The fix involves moving the warning trigger outside of the critical section protected by the spinlock.
Affected products
- Linux Linux Kernel 5.4 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-07-31: other: Patch submitted by Breno Leitao
- 2025-08-05: patched: Committed to mainline kernel
- 2025-09-11: disclosed: CVE published
References
- https://git.kernel.org/stable/c/08f70be5e406ce47c822f2dd11c1170ca259605b
- https://git.kernel.org/stable/c/1da95d3d4b7b1d380ebd87b71a61e7e6aed3265d
- https://git.kernel.org/stable/c/47b0f6d8f0d2be4d311a49e13d2fd5f152f492b2
- https://git.kernel.org/stable/c/4b0151e1d468eb2667c37b7af99b3c075072d334
- https://git.kernel.org/stable/c/62879faa8efe8d8a9c7bf7606ee9c068012d7dac
- https://git.kernel.org/stable/c/a0854de00ce2ee27edf39037e7836ad580eb3350
- https://git.kernel.org/stable/c/a181b228b37a6a5625dad2bb4265bb7abb673e9f