Junglewise Threat Intelligence

CVE-2026-63839: Linux Kernel memory leak in lenovo-wmi-helpers

CVE-2026-63839 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak was identified in the Linux kernel's Lenovo WMI helper component, which manages communication between the operating system and hardware features on Lenovo laptops. If triggered repeatedly, this flaw could gradually consume system memory, potentially leading to reduced system performance or instability. The issue has been resolved in recent kernel updates.

Technical details

A memory leak exists in the 'lwmi_dev_evaluate_int' function within 'drivers/platform/x86/lenovo/wmi-helpers.c'. The vulnerability occurs because 'output.pointer' is only assigned to a cleanup-managed variable ('ret_obj') when 'retval' is non-NULL. If 'retval' is NULL, the allocated ACPI buffer is never freed, leading to a leak. This is a local vulnerability that can be triggered during WMI method evaluations. The fix involves moving the assignment of 'output.pointer' to 'ret_obj' outside of the conditional block to ensure the '__free(kfree)' cleanup callback always executes.

Affected products

  • Linux Linux Kernel 6.17 to 7.0.10

Timeline

  • 2026-05-10: disclosed: Initial patch submitted by Rong Zhang
  • 2026-07-19: advisory: CVE-2026-63839 published by kernel.org and NVD

References

Related threats