NONE · 0

CVE-2026-53213

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: fix krealloc() memory leak Don't just overwrite the original pointer passed to krealloc() with its return value without c...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: fix krealloc() memory leak Don't just overwrite the original pointer passed to krealloc() with its return value without checking latter: MEM = krealloc(MEM, SZ, GFP); If krealloc() returns NULL, that erases the pointer to the still allocated memory, hence leaks this memory. Instead, use a temporary variable, check it's not NULL and only then assign it to the original pointer: TMP = krealloc(MEM, SZ, GFP); if (!TMP) return; MEM = TMP; While on it, use krealloc_array().

References

FAQ

What is CVE-2026-53213?

CVE-2026-53213 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: drm/vc4: fix krealloc() memory leak Don't just overwrite the original pointer passed to krealloc() with its return value without c...

How severe is CVE-2026-53213?

CVSS scoring is not yet available for CVE-2026-53213. Check NVD for updates.

Is there a patch for CVE-2026-53213?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.