SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64180

MEDIUM · CVSS 5.5 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's memory hotplug functionality, specifically related to memory block reference management during the removal process. The impact includes potential memory leaks due to untracked references, which could lead to resource exhaustion or instability in systems utilizing memory hotplug features. System administrators and developers managing Linux environments with dynamic memory configurations should prioritize applying the patch to mitigate these risks.

CVE
CVE-2026-64180
Severity
MEDIUM
CVSS
5.5
EPSS
0.11%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: mm/memory_hotplug: fix memory block reference leak on remove Patch series "mm: Fix memory block leaks and locking", v2. This series fixes two memory block device reference leaks and one locking issue around the per-memory_block hwpoison counter. This patch (of 2): remove_memory_blocks_and_altmaps() looks up each memory block with find_memory_block(), which acquires a reference to the memory block device. That reference is never dropped on this path, resulting in a leaked device reference when removing memory blocks and their altmaps. Drop the reference after retrieving mem->altmap and clearing mem->altmap, before removing the memory block device.

Related CVEs

Other vulnerabilities affecting the same vendor(s)