Junglewise Threat Intelligence

CVE-2026-72168: Linux kernel vmu-flash uninitialized memory access in MTD mapping

CVE-2026-72168 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Dreamcast VMU flash memory driver (vmu-flash) incorrectly allocated memory for device structure initialization, leaving some fields uninitialized. This could cause runtime faults or information disclosure when the flash memory management layer queries protected device information. Systems running vulnerable kernel versions with Dreamcast VMU hardware attached are at risk of system instability.

Technical details

The vulnerability is an uninitialized memory disclosure in the vmu-flash MTD driver. The vulnerable code used kmalloc() (which does not zero memory) instead of kzalloc() (which does) when allocating memcard, vmupart, and mtd_info structures during the vmu_connect() device initialization path. Attackers with local access or kernel code triggering the mtd_get_fact_prot_info operation could read uninitialized stack or heap data. The fix changes three kmalloc/kmalloc_array calls to kzalloc/kzalloc_objs to ensure all allocated memory is zeroed before use. No remote attack vector; requires local code execution or specific hardware integration. Patch available in upstream Linux and stable branches.

Affected products

  • Linux Linux kernel Multiple stable branches from 2.6.x through 6.x

Timeline

  • 2026-08-15: disclosed
  • 2026-07-25: patched: Fix authored by Florian Fuchs

References

Related threats