Back

orangefs: Fix kmemleak in orangefs_prepare_debugfs_help_string()

Published Dec 24, 2025

Description

When insert and remove the orangefs module, then debug_help_string will be leaked:

unreferenced object 0xffff8881652ba000 (size 4096): comm "insmod", pid 1701, jiffies 4294893639 (age 13218.530s) hex dump (first 32 bytes): 43 6c 69 65 6e 74 20 44 65 62 75 67 20 4b 65 79 Client Debug Key 77 6f 72 64 73 20 61 72 65 20 75 6e 6b 6e 6f 77 words are unknow backtrace: [<0000000004e6f8e3>] kmalloc_trace+0x27/0xa0 [<0000000006f75d85>] orangefs_prepare_debugfs_help_string+0x5e/0x480 [orangefs] [<0000000091270a2a>] _sub_I_65535_1+0x57/0xf70 [crc_itu_t] [<000000004b1ee1a3>] do_one_initcall+0x87/0x2a0 [<000000001d0614ae>] do_init_module+0xdf/0x320 [<00000000efef068c>] load_module+0x2f98/0x3330 [<000000006533b44d>] __do_sys_finit_module+0x113/0x1b0 [<00000000a0da6f99>] do_syscall_64+0x35/0x80 [<000000007790b19b>] entry_SYSCALL_64_after_hwframe+0x46/0xb0

When remove the module, should always free debug_help_string. Should always free the allocated buffer when change the free_debug_help_string.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (15)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Dec 24, 2025
Updated May 11, 2026
Reserved Dec 24, 2025

CISA Vulnrichment

No data

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

Public date Dec 24, 2025
Bugzilla 2425093

ENISA EUVD

Assigner Linux
Published Dec 24, 2025
Updated May 11, 2026

GitHub

No data