Junglewise Threat Intelligence

CVE-2026-93049: Linux kernel mtdswap double-free in device registration

CVE-2026-93049 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's mtdswap driver contains a double-free vulnerability in its device initialization logic. When debugfs setup fails after successful block device registration, the device object is freed twice, potentially leading to kernel memory corruption or denial of service. This affects systems using MTD-based swap devices, particularly embedded systems with flash storage.

Technical details

The vulnerability is a use-after-free / double-free in the mtdswap_add_mtd() function. When add_mtd_blktrans_dev() succeeds and registers the blktrans device, the reference count is managed by the block translation layer. If subsequent debugfs setup fails, the code calls del_mtd_blktrans_dev() to unregister and drop the reference, which eventually frees the mtd_blktrans_dev object via blktrans_dev_release(). However, the code then falls through to a common cleanup label that calls kfree(mbd_dev) again on the already-freed pointer, causing a double-free. The fix clears the local mbd_dev pointer after deregistration so the cleanup path does not attempt to free it again. No authentication or network access is required; the vulnerability is triggered during normal device initialization when debugfs configuration encounters an error.

Affected products

  • Linux Linux kernel versions prior to fix commit 779aa4c66a96bf43d2d62982ea1a9096a9128d87

Timeline

  • 2026-09-17: disclosed

References

Related threats