Junglewise Threat Intelligence

CVE-2026-53127: Linux Kernel memory leak in block zone revalidation

CVE-2026-53127 · Severity: info · CVSS 2.1 · Published 2026-06-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's block storage subsystem where certain error conditions during disk zone revalidation could lead to a memory leak. This affects systems using zoned storage devices, potentially leading to a gradual depletion of system memory if revalidation errors occur repeatedly. While not typically leading to a full system crash immediately, it can impact long-term system stability and performance.

Technical details

A memory leak exists in block/blk-zoned.c within the Linux kernel. When blk_revalidate_disk_zones() fails after disk_revalidate_zone_resources() has successfully allocated the args.zones_cond array, the memory is not freed in the subsequent error handling paths. This vulnerability is specific to the management of zoned block devices. An attacker with the ability to trigger repeated disk revalidation cycles (e.g., through specific hardware events or administrative interfaces) could cause kernel memory exhaustion. The issue has been resolved by adding explicit kfree() calls in the error paths of the affected functions.

Affected products

  • Linux Linux 6.19 to 7.0.10

Timeline

  • 2026-03-31: patched: Initial fix committed to mainline kernel tree.
  • 2026-06-24: disclosed: CVE published to NVD.

References