Back

MEDIUM

wwan_hwsim: fix possible memory leak in wwan_hwsim_dev_new()

Published Sep 15, 2025

Description

Inject fault while probing module, if device_register() fails, but the refcount of kobject is not decreased to 0, the name allocated in dev_set_name() is leaked. Fix this by calling put_device(), so that name can be freed in callback function kobject_cleanup().

unreferenced object 0xffff88810152ad20 (size 8): comm "modprobe", pid 252, jiffies 4294849206 (age 22.713s) hex dump (first 8 bytes): 68 77 73 69 6d 30 00 ff hwsim0.. backtrace: [<000000009c3504ed>] __kmalloc_node_track_caller+0x44/0x1b0 [<00000000c0228a5e>] kvasprintf+0xb5/0x140 [<00000000cff8c21f>] kvasprintf_const+0x55/0x180 [<0000000055a1e073>] kobject_set_name_vargs+0x56/0x150 [<000000000a80b139>] dev_set_name+0xab/0xe0

Affected products

Remediation

Red Hat statement

The bug causes a small memory leak in the wwan_hwsim simulator when device_register() fails, due to using kfree() instead of put_device(). This prevents proper cleanup of the kobject name. Exploitation is not realistic: it requires privileged module loading and only results in minor memory leakage on error paths, without impact on confidentiality or integrity.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 15, 2025
Updated May 11, 2026
Reserved Sep 15, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 15, 2025