cbcvebase.
CVE-2026-23260
published 2026-03-18

CVE-2026-23260: In the Linux kernel, the following vulnerability has been resolved: regmap: maple: free entry on mas_store_gfp() failure regcache_maple_write() allocates a new…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved: regmap: maple: free entry on mas_store_gfp() failure regcache_maple_write() allocates a new block ('entry') to merge adjacent ranges and then stores it with mas_store_gfp(). When mas_store_gfp() fails, the new 'entry' remains allocated and is never freed, leaking memory. Free 'entry' on the failure path; on success continue freeing the replaced neighbor blocks ('lower', 'upper').

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.10-1 (forky)linux 6.18.10-1 (forky)
linuxlinux
linuxlinux>= f033c26de5a5734625d2dd1dc196745fae186f1b < d61171cf097156030142643942c217759a9cc806d61171cf097156030142643942c217759a9cc806
linuxlinux>= f033c26de5a5734625d2dd1dc196745fae186f1b < 811b45e2d795d955bb7fd9c816b40036f4fde350811b45e2d795d955bb7fd9c816b40036f4fde350
linuxlinux>= f033c26de5a5734625d2dd1dc196745fae186f1b < f08f2d2907675926ac5657b25f86d921f269602af08f2d2907675926ac5657b25f86d921f269602a
linuxlinux>= f033c26de5a5734625d2dd1dc196745fae186f1b < f3f380ce6b3d5c9805c7e0b3d5bc28d9ec41e2e8f3f380ce6b3d5c9805c7e0b3d5bc28d9ec41e2e8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 6.13 < 6.18.106.18.10
linuxlinux_kernel>= 6.13.0 < 6.18.106.18.10
linuxlinux_kernel>= 6.4 < 6.6.1246.6.124
linuxlinux_kernel>= 6.4.0 < 6.6.1246.6.124
linuxlinux_kernel>= 6.7 < 6.12.706.12.70
linuxlinux_kernel>= 6.7.0 < 6.12.706.12.70
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-fips
ubuntulinux-gke

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.8HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.