Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: soc: microchip: mpfs: Fix memory leak in mpfs_sys_controller_probe() In mpfs_sys_controller_probe(), if of_get_mtd_device_by_node() fails, the function returns immediately without freeing the allocated memory for sys_controller, leading to a memory leak. Fix this by jumping to the out_free label to ensure the memory is properly freed. Also, consolidate the error handling for the mbox_request_channel() failure case to use the same label.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.8, < 6.12.78 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/17c84fb7cf3971cc621646185d785670e9530ca1Patch
- https://git.kernel.org/stable/c/5a741f8cc6fe62542f955cd8d24933a1b6589cbdPatch
- https://git.kernel.org/stable/c/da4b44c42f40501db35f5d0a6243708a061490a0Patch
- https://git.kernel.org/stable/c/e3dd5cffba07de6574165a72851471cd42cc6d15Patch
FAQ
What is CVE-2026-23464?
CVE-2026-23464 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: soc: microchip: mpfs: Fix memory leak in mpfs_sys_controller_probe() In mpfs_sys_controller_probe(), if of_get_mtd_device_by_node(...
How severe is CVE-2026-23464?
CVE-2026-23464 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-23464?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.