Linux Kernel nvmet Memory Leak Vulnerability

Vulnerability

A memory leak vulnerability has been identified in the Linux kernel's nvmet component. This issue arises when changing DH-CHAP secrets, as the old secrets are not properly released, leading to a memory leak. The kernel memory leak was detected by the kernel memory leak tracker, which reported an unreferenced object that had not been freed. The backtrace indicates that the memory leak occurs during the process of writing configuration changes, which can be triggered by user-space applications.

Impact

Exploitation of this vulnerability leads to a memory leak, where allocated memory is not properly released, potentially causing increased memory usage and degradation of system performance over time.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.