{"id":"CVE-2026-68416","summary":"mtd: fix double free and WARN_ON in add_mtd_device() error paths","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: fix double free and WARN_ON in add_mtd_device() error paths\n\nWhen device_register() or mtd_nvmem_add() fails inside\nadd_mtd_device() for a partition, the error handling triggers\nmtd_release() via put_device() or device_unregister(). mtd_release()\ncalls release_mtd_partition() which frees the mtd_info structure.\nHowever, callers such as mtd_add_partition() and add_mtd_partitions()\nalso call free_partition() in their error paths, resulting in a double\nfree.\n\nAdditionally, release_mtd_partition() hits WARN_ON(!list_empty(\n&mtd-\u003epart.node)) because the partition node is still linked in the\nparent's partitions list when the release callback fires from the\nadd_mtd_device() error path.\n\nFix this by overriding dev-\u003etype and dev-\u003erelease before put_device()\nin the error paths, so that device_release() invokes a no-op function\ninstead of mtd_release(). For the mtd_nvmem_add() failure case,\ndevice_unregister() is replaced with device_del() to separate the\ndevice removal from the final kobject reference drop, allowing the\noverride to take effect before put_device() is called.\n\nThe callers' error paths (list_del + free_partition) remain the sole\nowners of mtd_info lifetime on add_mtd_device() failure, which is the\nexpected contract.\n\nThe normal partition teardown path is not affected: del_mtd_device()\ngoes through kref_put() -\u003e mtd_device_release() -\u003e device_unregister()\nwith dev-\u003etype still set to &mtd_devtype, so mtd_release() -\u003e\nrelease_mtd_partition() continues to work correctly for the regular\nremoval case.","modified":"2026-08-12T04:24:33.091569600Z","published":"2026-08-10T12:04:36.582Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68416.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/820f983d641937a787e841ee4b93501f69f5683e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9d4af746af8ce27eefc2338b2feaa1e01f28b6c3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e1e96aca1bdf391e2f49531c270ffc134e5b49a5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f98ae09c727dcf34f745c875661c64b642e4abfa"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ffe21a3545b439e7b11578a701c22a847c149561"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68416.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68416"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"19bfa9ebebb5ec0695def57eb1d80de7e9cab369"},{"fixed":"ffe21a3545b439e7b11578a701c22a847c149561"},{"fixed":"e1e96aca1bdf391e2f49531c270ffc134e5b49a5"},{"fixed":"f98ae09c727dcf34f745c875661c64b642e4abfa"},{"fixed":"820f983d641937a787e841ee4b93501f69f5683e"},{"fixed":"9d4af746af8ce27eefc2338b2feaa1e01f28b6c3"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68416.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.6.0"},{"fixed":"6.6.148"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.101"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.42"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68416.json"}}],"schema_version":"1.9.0"}