Junglewise Threat Intelligence

CVE-2026-64509: Linux Kernel resource leak in Rust block GenDisk cleanup

CVE-2026-64509 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Rust-based block device subsystem. This issue could lead to memory leaks or resource exhaustion when the system fails to properly clean up disk structures during certain error conditions. While primarily a stability concern, it could impact system availability or performance over time.

Technical details

A vulnerability in the Rust block device abstraction (`rust/kernel/block/mq/gen_disk.rs`) in the Linux kernel leads to resource leaks. Specifically, `GenDiskBuilder::build()` fails to properly drop the temporary `gendisk` and `request_queue` references during fallible operations following `__blk_mq_alloc_disk()`. Additionally, the `Drop` implementation for `GenDisk` failed to call `put_disk()` after `del_gendisk()`, preventing the final release path from executing. This can result in leaked `blk-mq` state and memory. The issue has been resolved by implementing proper `ScopeGuard` cleanup paths and ensuring `put_disk()` is called to trigger the full release sequence.

Affected products

  • Linux Linux Kernel 6.11, 6.12, 7.1

Timeline

  • 2026-07-25: advisory: NVD publication date
  • 2026-05-31: patched: Initial fix committed to mainline kernel by Jens Axboe

References

Related threats