cbcvebase.
CVE-2026-23164
published 2026-02-14

CVE-2026-23164: In the Linux kernel, the following vulnerability has been resolved: rocker: fix memory leak in rocker_world_port_post_fini() In rocker_world_port_pre_init()…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.8th percentile
In the Linux kernel, the following vulnerability has been resolved: rocker: fix memory leak in rocker_world_port_post_fini() In rocker_world_port_pre_init(), rocker_port->wpriv is allocated with kzalloc(wops->port_priv_size, GFP_KERNEL). However, in rocker_world_port_post_fini(), the memory is only freed when wops->port_post_fini callback is set: if (!wops->port_post_fini) return; wops->port_post_fini(rocker_port); kfree(rocker_port->wpriv); Since rocker_ofdpa_ops does not implement port_post_fini callback (it is NULL), the wpriv memory allocated for each port is never freed when ports are removed. This leads to a memory leak of sizeof(struct ofdpa_port) bytes per port on every device removal. Fix this by always calling kfree(rocker_port->wpriv) regardless of whether the port_post_fini callback exists.

Affected

61 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= e420114eef4a3a5025a243b89b0dc343101e3d3c < 2a3a64d75d2d0727da285749476761ebcad557a32a3a64d75d2d0727da285749476761ebcad557a3
linuxlinux>= e420114eef4a3a5025a243b89b0dc343101e3d3c < b11e6f926480ab0939fec44781f28558c54be4e7b11e6f926480ab0939fec44781f28558c54be4e7
linuxlinux>= e420114eef4a3a5025a243b89b0dc343101e3d3c < 8ce2e85889939c02740b4245301aa5c35fc948878ce2e85889939c02740b4245301aa5c35fc94887
linuxlinux>= e420114eef4a3a5025a243b89b0dc343101e3d3c < d448bf96889f1905e740c554780f5c9fa0440566d448bf96889f1905e740c554780f5c9fa0440566
linuxlinux>= e420114eef4a3a5025a243b89b0dc343101e3d3c < d8723917efda3b4f4c3de78d1ec1e1af015c0be1d8723917efda3b4f4c3de78d1ec1e1af015c0be1
linuxlinux>= e420114eef4a3a5025a243b89b0dc343101e3d3c < dce375f4afc348c310d171abcde7ec1499a4c26adce375f4afc348c310d171abcde7ec1499a4c26a
linuxlinux>= e420114eef4a3a5025a243b89b0dc343101e3d3c < 8d7ba71e46216b8657a82ca2ec118bc93812a4d08d7ba71e46216b8657a82ca2ec118bc93812a4d0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.9-16.18.9-1
linuxlinux_kernel>= 4.6 < 5.10.2495.10.249
linuxlinux_kernel>= 5.11 < 5.15.1995.15.199
linuxlinux_kernel>= 5.16 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13 < 6.18.96.18.9
linuxlinux_kernel>= 6.2 < 6.6.1236.6.123
linuxlinux_kernel>= 6.7 < 6.12.696.12.69
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.