Executive brief
A memory leak vulnerability was identified in the Linux kernel's TP-Link SafeLoader partition parser. This component is responsible for identifying how data is organized on certain networking hardware storage. While the practical impact is low, a memory leak can slowly consume system resources, potentially leading to reduced performance or system instability over long periods of operation.
Technical details
A memory leak exists in the 'mtd_parser_tplink_safeloader_parse' function within 'drivers/mtd/parsers/tplink_safeloader.c'. The function allocates a temporary buffer ('buf') via 'mtd_parser_tplink_safeloader_read_table()'. If a subsequent memory allocation for a partition name ('parts[idx].name') fails within the parsing loop, the code execution jumps to an error handling label ('err_free') that fails to release the 'buf' memory. This is a local vulnerability requiring the ability to trigger partition parsing, typically during device initialization or disk mounting. Patches have been merged into multiple stable kernel branches to ensure 'kfree(buf)' is called during error handling.
Affected products
- Linux Linux Kernel Fixed in various stable branches including 6.x and 5.x
Timeline
- 2026-01-22: disclosed: Initial patch submitted by Zilin Guan
- 2026-05-27: advisory: CVE-2026-45921 published via NVD
References
- https://git.kernel.org/stable/c/0f5e62ea5c43146eacdc6861cb1022ffae1b79bc
- https://git.kernel.org/stable/c/971e9c53aed82f17a9c6a65daa4e21cc15eba5b1
- https://git.kernel.org/stable/c/980ce2b02dd06a4fdf5fee38b2e14becf9cf7b8b
- https://git.kernel.org/stable/c/e97f5fac8ce9a6b9ec724c97d86b0985e915fdca
- https://git.kernel.org/stable/c/ec121ad626c319085f6d40a52cd04e99b4554926