Vulnerabilities
CVE-2026-23032 - null_blk: fix kmemleak by releasing references to fault configfs items
CVE ID : CVE-2026-23032 Published : Jan. 31, 2026, 12:16 p.m. | 29 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: null_blk: fix kmemleak by releasing references to fault configfs items When CONFIG_BLK_DEV_NULL_BLK_FAULT_INJECTION is enabled, the null-blk driver sets up fault injection support by creating the timeout_inject, requeue_inject, and init_hctx_fault_inject configfs items as children of the top-level nullbX configfs group. However, when the nullbX device is removed, the references taken to these fault-config configfs items are not released. As a result, kmemleak reports a memory leak, for example: unreferenced object 0xc00000021ff25c40 (size 32): comm