Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_or_reset() already invokes the action on failure, so the explicit put causes a double-put.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.6.118, < 6.6.130 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/188ba3468cb7c098c62609d82e9fc58d29ead7f4Patch
- https://git.kernel.org/stable/c/1e0465139fd9caee7ffefe285ef7d5f21919e474Patch
- https://git.kernel.org/stable/c/95b14ecc56881dd9a187e1e84dd0daa88ff22c5dPatch
- https://git.kernel.org/stable/c/ea07fcfbba4301839db3784f09955d9fa3e98090Patch
- https://git.kernel.org/stable/c/fd5bed798f45eb3a178ad527b43ab92705faaf8aPatch
FAQ
What is CVE-2026-23387?
CVE-2026-23387 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_or_reset() already invokes the action on failure, ...
How severe is CVE-2026-23387?
CVE-2026-23387 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-23387?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.