CVE-2026-23137

CWE-401Memory Leak8 documents8 sources
Severity
5.5MEDIUM
EPSS
0.0%
top 96.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14

Description

In the Linux kernel, the following vulnerability has been resolved: of: unittest: Fix memory leak in unittest_data_add() In unittest_data_add(), if of_resolve_phandles() fails, the allocated unittest_data is not freed, leading to a memory leak. Fix this by using scope-based cleanup helper __free(kfree) for automatic resource cleanup. This ensures unittest_data is automatically freed when it goes out of scope in error paths. For the success path, use retain_and_null_ptr() to transfer ownershi

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel3.186.18.6+1
CVEListV5linux/linux2eb46da2a760e5764c48b752a5ef320e02b96b21f09b0f705bd7197863b90256ef533a6414d1db2c+2
Debianlinux< 6.18.8-1

Patches

🔴Vulnerability Details

3
CVEList
of: unittest: Fix memory leak in unittest_data_add()2026-02-14
GHSA
GHSA-rwc9-h9mh-xfwq: In the Linux kernel, the following vulnerability has been resolved: of: unittest: Fix memory leak in unittest_data_add() In unittest_data_add(), if2026-02-14
OSV
CVE-2026-23137: In the Linux kernel, the following vulnerability has been resolved: of: unittest: Fix memory leak in unittest_data_add() In unittest_data_add(), if of2026-02-14

📋Vendor Advisories

3
Red Hat
kernel: of: unittest: Fix memory leak in unittest_data_add()2026-02-14
Microsoft
of: unittest: Fix memory leak in unittest_data_add()2026-02-10
Debian
CVE-2026-23137: linux - In the Linux kernel, the following vulnerability has been resolved: of: unittes...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23137 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23137 (MEDIUM CVSS 5.5) | In the Linux kernel | cvebase.io