cbcvebase.
CVE-2026-23021
published 2026-01-31

CVE-2026-23021: In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: fix memory leak in update_eth_regs_async() When asynchronously writing…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: fix memory leak in update_eth_regs_async() When asynchronously writing to the device registers and if usb_submit_urb() fail, the code fail to release allocated to this point resources.

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 323b34963d113efb566635f43858f40cce01d5f9 < 5397ea6d21c35a17707e201a60761bdee00bcc4e5397ea6d21c35a17707e201a60761bdee00bcc4e
linuxlinux>= 323b34963d113efb566635f43858f40cce01d5f9 < a40af9a2904a1ab8ce61866ebe2a894ef30754baa40af9a2904a1ab8ce61866ebe2a894ef30754ba
linuxlinux>= 323b34963d113efb566635f43858f40cce01d5f9 < ac5d92d2826dec51e5d4c6854865bc5817277452ac5d92d2826dec51e5d4c6854865bc5817277452
linuxlinux>= 323b34963d113efb566635f43858f40cce01d5f9 < 93f18eaa190374e0f2d253e3b1a65cee19a7abe693f18eaa190374e0f2d253e3b1a65cee19a7abe6
linuxlinux>= 323b34963d113efb566635f43858f40cce01d5f9 < 471dfb97599eec74e0476046b3ef8e7037f27b34471dfb97599eec74e0476046b3ef8e7037f27b34
linuxlinux>= 323b34963d113efb566635f43858f40cce01d5f9 < ce6eef731aba23a988decea1df3b08cf978f7b01ce6eef731aba23a988decea1df3b08cf978f7b01
linuxlinux>= 323b34963d113efb566635f43858f40cce01d5f9 < afa27621a28af317523e0836dad430bec551eb54afa27621a28af317523e0836dad430bec551eb54
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 3.10.0 < 5.10.2485.10.248
linuxlinux_kernel>= 3.10.1 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11 < 5.15.1985.15.198
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16 < 6.1.1616.1.161
linuxlinux_kernel>= 5.16.0 < 6.1.1616.1.161
linuxlinux_kernel>= 6.13 < 6.18.66.18.6
linuxlinux_kernel>= 6.13.0 < 6.18.66.18.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.