CVE-2026-45997: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails If device_add(&sdkp->disk_dev) fails, put_device() runs scsi_disk_release(), which frees the scsi_disk but leaves the gendisk referenced. The device_add_disk() error path in sd_probe() calls put_disk(gd); call put_disk(gd) here to mirror that cleanup.
Affected products
- Linux Linux Kernel: from 4.4.288, before 4.5 (fixed in 4.5); from 4.9.286, before 4.10 (fixed in 4.10); from 4.14.250, before 4.15 (fixed in 4.15); from 4.19.210, before 4.20 (fixed in 4.20); from 5.4.152, before 5.5 (fixed in 5.5); from 5.10.72, before 5.11 (fixed in 5.11); …
Published 2026-05-27. Last modified 2026-06-17.