CVE-2026-23305 — Missing Release of Resource after Effective Lifetime in Linux
Severity
5.3MEDIUM
No vectorEPSS
0.0%
top 94.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 25
Description
In the Linux kernel, the following vulnerability has been resolved:
accel/rocket: fix unwinding in error path in rocket_probe
When rocket_core_init() fails (as could be the case with EPROBE_DEFER),
we need to properly unwind by decrementing the counter we just
incremented and if this is the first core we failed to probe, remove the
rocket DRM device with rocket_device_fini() as well. This matches the
logic in rocket_remove(). Failing to properly unwind results in
out-of-bounds accesses.
Affected Packages4 packages
▶CVEListV5linux/linux0810d5ad88a18f1e6d549853a388ad0316f74e36 — 7fc4b49474c836cee7d9801abf05e0198fcbfa74+3
🔴Vulnerability Details
3OSV▶
CVE-2026-23305: In the Linux kernel, the following vulnerability has been resolved: accel/rocket: fix unwinding in error path in rocket_probe When rocket_core_init()↗2026-03-25
GHSA▶
GHSA-82hq-cx37-5qm5: In the Linux kernel, the following vulnerability has been resolved:
accel/rocket: fix unwinding in error path in rocket_probe
When rocket_core_init(↗2026-03-25