Executive brief
The Linux kernel's Lenovo think-lmi driver (used to manage Lenovo system firmware settings) fails to free memory allocated for system certificate signatures when the driver is unloaded. This causes a memory leak that accumulates over time, potentially degrading system performance if the driver is repeatedly loaded and unloaded.
Technical details
This is a memory leak vulnerability (CWE-401) in the think-lmi platform/x86 driver. When multi-certificate support was added, the system authentication object began storing signature and save_signature pointers, but the tlmi_release_attr() cleanup function did not free these for the system password object, only for the admin password object. The vulnerable component is drivers/platform/x86/lenovo/think-lmi.c. The leak occurs locally during driver removal with no authentication or network requirements. An attacker with local access could repeatedly load/unload the driver to exhaust kernel memory and trigger a denial of service. A patch was committed by Thorsten Blum adding kfree() calls for the system certificate signatures.
Affected products
- Linux Linux kernel Affected versions include those with commit 5dcb5ef12590 (multi-certificate support) through the patch date; typical stable branches 4.19.y through 6.x.y and beyond
Timeline
- 2026-09-11: disclosed
- 2026-09-07: patched: Patch committed to stable kernel branches