Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() Fix a memory leak in gpi_peripheral_config() where the original memory pointed to by gchan->config could be lost if krealloc() fails. The issue occurs when: 1. gchan->config points to previously allocated memory 2. krealloc() fails and returns NULL 3. The function directly assigns NULL to gchan->config, losing the reference to the original memory 4. The original memory becomes unreachable and cannot be freed Fix this by using a temporary variable to hold the krealloc() result and only updating gchan->config when the allocation succeeds. Found via static analysis and code review.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.11.1, < 5.15.199 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/01b1d781394fc9b83015e3a3cd46b17bda842bd8Patch
- https://git.kernel.org/stable/c/3f747004bbd641131d9396d87b5d2d3d1e182728Patch
- https://git.kernel.org/stable/c/4532f18e4ab36def1f55cd936d0fc002b2ce34c2Patch
- https://git.kernel.org/stable/c/55a67ba5ac4cebfd54cc8305d4d57a0f1dfe6a85Patch
- https://git.kernel.org/stable/c/694ab1f6f16cb69f7c5ef2452b22ba7b00a3c7c7Patch
- https://git.kernel.org/stable/c/6bf4ef078fd11910988889a6c0b3698d2e0c89afPatch
FAQ
What is CVE-2026-23026?
CVE-2026-23026 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() Fix a memory leak in gpi_peripheral_config() where the original m...
How severe is CVE-2026-23026?
CVE-2026-23026 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-23026?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.