CVE-2026-23026Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 99.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31
Latest updateApr 17

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() Fix a memory leak in gpi_peripheral_config() where the original memory pointed to by gchan->config could be lost if krealloc() fails. The issue occurs when: 1. gchan->config points to previously allocated memory 2. krealloc() fails and returns NULL 3. The function directly assigns NULL to gchan->config, losing the reference to the original memory 4. The original

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages13 packages

Linuxlinux/linux_kernel5.11.05.15.199+4
NVDlinux/linux_kernel5.11.15.15.199+6
Debianlinux/linux_kernel< 6.1.162-1+2
CVEListV5linux/linux5d0c3533a19f48e5e7e73806a3e4b29cd43641304532f18e4ab36def1f55cd936d0fc002b2ce34c2+6
debiandebian/linux< linux 6.1.162-1 (bookworm)

Patches

🔴Vulnerability Details

3
OSV
CVE-2026-23026: In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() Fix a memory leak2026-01-31
OSV
dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config()2026-01-31
GHSA
GHSA-r4rx-4jr3-hmp7: In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() Fix a memory le2026-01-31

📋Vendor Advisories

8
Ubuntu
Linux kernel (HWE) vulnerabilities2026-04-17
Ubuntu
Linux kernel (NVIDIA) vulnerabilities2026-04-17
Ubuntu
Linux kernel (FIPS) vulnerabilities2026-04-17
Ubuntu
Linux kernel (Real-time) vulnerabilities2026-04-17
Ubuntu
Linux kernel vulnerabilities2026-04-16

🕵️Threat Intelligence

1
Wiz
CVE-2026-23026 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23026 — Linux vulnerability | cvebase