Executive brief
A vulnerability was identified in the Linux kernel's Rust-based block device subsystem. This issue could lead to memory leaks or resource exhaustion when the system fails to properly clean up disk structures during certain error conditions. While primarily a stability concern, it could impact system availability or performance over time.
Technical details
A vulnerability in the Rust block device abstraction (`rust/kernel/block/mq/gen_disk.rs`) in the Linux kernel leads to resource leaks. Specifically, `GenDiskBuilder::build()` fails to properly drop the temporary `gendisk` and `request_queue` references during fallible operations following `__blk_mq_alloc_disk()`. Additionally, the `Drop` implementation for `GenDisk` failed to call `put_disk()` after `del_gendisk()`, preventing the final release path from executing. This can result in leaked `blk-mq` state and memory. The issue has been resolved by implementing proper `ScopeGuard` cleanup paths and ensuring `put_disk()` is called to trigger the full release sequence.
Affected products
- Linux Linux Kernel 6.11, 6.12, 7.1
Timeline
- 2026-07-25: advisory: NVD publication date
- 2026-05-31: patched: Initial fix committed to mainline kernel by Jens Axboe