CVE-2026-98227: memstick: ms_block: destroy io_queue workqueue on removal
In the Linux kernel, the following vulnerability has been resolved:
memstick: msblock: destroy ioqueue workqueue on removal
msbinitdisk() creates the per-card ordered workqueue msb->ioqueue with allocorderedworkqueue(). It is torn down with destroyworkqueue() only on the init error path; msbremove() never destroys it. msbstop() merely flushes the queue, and neither msbdataclear() nor putdisk() free it. As a result every card insert/remove cycle leaks the workqueue and its kworker, exhausting kernel memory over repeated cycles.
Destroy the workqueue in msbremove() after the disk has been removed and the queue drained.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In memstick ms_block, update msb_remove() to call destroy_workqueue(msb->io_queue) after the disk has been removed, ensuring the per-card ordered workqueue created by msb_init_disk() is freed on every removal cycle.