Executive brief
A memory leak vulnerability was identified in the Linux kernel's NX-842 hardware compression driver. This component is responsible for accelerating data compression tasks. The flaw causes the system to fail to properly reclaim memory when certain cryptographic operations are finished or encounter errors, which could eventually lead to system instability or performance degradation as available memory is exhausted.
Technical details
A memory leak exists in the nx842_crypto_alloc_ctx and nx842_crypto_free_ctx functions within drivers/crypto/nx/nx-842.c. The vulnerability is caused by a mismatch in memory management functions: bounce buffers are allocated using __get_free_pages() with an order of 2 (4 pages), but are released using free_page() instead of free_pages(). This results in only the first page being freed while the remaining pages in the allocation order are leaked. An attacker with the ability to trigger repeated allocation and deallocation of these crypto contexts could cause kernel memory exhaustion. The issue has been resolved by ensuring free_pages() is used with the correct BOUNCE_BUFFER_ORDER.
Affected products
- Linux Linux kernel All versions prior to the fix in May 2026
Timeline
- 2026-03-11: other: Patch authored
- 2026-05-27: advisory: CVE-2026-46068 published
References
- https://git.kernel.org/stable/c/5c07962fed66e1238fad7635fa150570bd38b4c5
- https://git.kernel.org/stable/c/80fd99d7c30ea889662d21f1b44d8fea4c83138d
- https://git.kernel.org/stable/c/910bb34b801d39794e656f7d48414844b2bd354e
- https://git.kernel.org/stable/c/adb3faf2db1a66d0f015b44ac909a32dfc7f2f9c
- https://git.kernel.org/stable/c/f17a4850d1ce7c11cba8b1830b9bfedfede878bb