{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "19bfa9ebebb5ec0695def57eb1d80de7e9cab369"
            },
            {
              "fixed": "ffe21a3545b439e7b11578a701c22a847c149561"
            },
            {
              "fixed": "e1e96aca1bdf391e2f49531c270ffc134e5b49a5"
            },
            {
              "fixed": "f98ae09c727dcf34f745c875661c64b642e4abfa"
            },
            {
              "fixed": "820f983d641937a787e841ee4b93501f69f5683e"
            },
            {
              "fixed": "9d4af746af8ce27eefc2338b2feaa1e01f28b6c3"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.6.0"
            },
            {
              "fixed": "6.6.148"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.101"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.42"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.1.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68416.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: fix double free and WARN_ON in add_mtd_device() error paths\n\nWhen device_register() or mtd_nvmem_add() fails inside\nadd_mtd_device() for a partition, the error handling triggers\nmtd_release() via put_device() or device_unregister(). mtd_release()\ncalls release_mtd_partition() which frees the mtd_info structure.\nHowever, callers such as mtd_add_partition() and add_mtd_partitions()\nalso call free_partition() in their error paths, resulting in a double\nfree.\n\nAdditionally, release_mtd_partition() hits WARN_ON(!list_empty(\n\u0026mtd-\u003epart.node)) because the partition node is still linked in the\nparent's partitions list when the release callback fires from the\nadd_mtd_device() error path.\n\nFix this by overriding dev-\u003etype and dev-\u003erelease before put_device()\nin the error paths, so that device_release() invokes a no-op function\ninstead of mtd_release(). For the mtd_nvmem_add() failure case,\ndevice_unregister() is replaced with device_del() to separate the\ndevice removal from the final kobject reference drop, allowing the\noverride to take effect before put_device() is called.\n\nThe callers' error paths (list_del + free_partition) remain the sole\nowners of mtd_info lifetime on add_mtd_device() failure, which is the\nexpected contract.\n\nThe normal partition teardown path is not affected: del_mtd_device()\ngoes through kref_put() -\u003e mtd_device_release() -\u003e device_unregister()\nwith dev-\u003etype still set to \u0026mtd_devtype, so mtd_release() -\u003e\nrelease_mtd_partition() continues to work correctly for the regular\nremoval case.",
  "id": "CVE-2026-68416",
  "modified": "2026-08-12T03:51:20.408265989Z",
  "published": "2026-08-10T12:04:36.582Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/820f983d641937a787e841ee4b93501f69f5683e"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/9d4af746af8ce27eefc2338b2feaa1e01f28b6c3"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/e1e96aca1bdf391e2f49531c270ffc134e5b49a5"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/f98ae09c727dcf34f745c875661c64b642e4abfa"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ffe21a3545b439e7b11578a701c22a847c149561"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68416.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68416"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "mtd: fix double free and WARN_ON in add_mtd_device() error paths"
}