CVE-2026-23314
published 2026-03-25CVE-2026-23314: In the Linux kernel, the following vulnerability has been resolved: regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio() In…
PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
In bq257xx_reg_dt_parse_gpio(), if fails to get subchild, it returns
without calling of_node_put(child), causing the device node reference
leak.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.8-1 (forky) | linux 6.19.8-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 981dd162b63578aee34b5c68795e246734b76d70 < 93b64bef8cd4074806d981ed1b4c38c3ae0542e3 | 93b64bef8cd4074806d981ed1b4c38c3ae0542e3 |
| linux | linux | >= 981dd162b63578aee34b5c68795e246734b76d70 < aba54a5a113667df9d339f4192650f6bc27e9d1f | aba54a5a113667df9d339f4192650f6bc27e9d1f |
| linux | linux | >= 981dd162b63578aee34b5c68795e246734b76d70 < 4baaddaa44af01cd4ce239493060738fd0881835 | 4baaddaa44af01cd4ce239493060738fd0881835 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.8-1 | 6.19.8-1 |
| linux | linux_kernel | >= 6.18.0 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.18.1 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.19 < 6.19.7 | 6.19.7 |
| linux | linux_kernel | >= 6.19.0 < 6.19.7 | 6.19.7 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.18.16/6.19.6/7.0-rc1 bq257xx_reg_dt_parse_gpio memory leak (Nessus ID 304084 / WID-SEC-2026-0861)
vuldb·2026-06-16·CVSS 5.5
CVE-2026-23314 [MEDIUM] Linux Kernel up to 6.18.16/6.19.6/7.0-rc1 bq257xx_reg_dt_parse_gpio memory leak (Nessus ID 304084 / WID-SEC-2026-0861)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.16/6.19.6/7.0-rc1. Affected by this issue is the function bq257xx_reg_dt_parse_gpio. Executing a manipulation can lead to memory leak.
This vulnerability appears as CVE-2026-23314. The attacker needs to be present on the local network. There is no available exploit.
You should upgrade the affected component.
OSV
regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
osv·2026-03-25
CVE-2026-23314 regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
In the Linux kernel, the following vulnerability has been resolved:
regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
In bq257xx_reg_dt_parse_gpio(), if fails to get subchild, it returns
without calling of_node_put(child), causing the device node reference
leak.
OSV
CVE-2026-23314: In the Linux kernel, the following vulnerability has been resolved: regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
osv·2026-03-25
CVE-2026-23314 CVE-2026-23314: In the Linux kernel, the following vulnerability has been resolved: regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
In the Linux kernel, the following vulnerability has been resolved: regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio() In bq257xx_reg_dt_parse_gpio(), if fails to get subchild, it returns without calling of_node_put(child), causing the device node reference leak.
GHSA
GHSA-mv9g-rfx4-jpcr: In the Linux kernel, the following vulnerability has been resolved:
regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
ghsa_unreviewed·2026-03-25
CVE-2026-23314 GHSA-mv9g-rfx4-jpcr: In the Linux kernel, the following vulnerability has been resolved:
regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
In the Linux kernel, the following vulnerability has been resolved:
regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
In bq257xx_reg_dt_parse_gpio(), if fails to get subchild, it returns
without calling of_node_put(child), causing the device node reference
leak.
Red Hat
kernel: regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
vendor_redhat·2026-03-25
CVE-2026-23314 CWE-772 kernel: regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
kernel: regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
In the Linux kernel, the following vulnerability has been resolved:
regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()
In bq257xx_reg_dt_parse_gpio(), if fails to get subchild, it returns
without calling of_node_put(child), causing the device node reference
leak.
A flaw was found in the Linux kernel, specifically within the `regulator: bq257xx` subsystem. This vulnerability, a device node reference leak, occurs when the `bq257xx_reg_dt_parse_gpio()` function fails to properly manage system resources. An attacker could potentially exploit this to cause a denial of service (DoS), making the system unresponsive.
Package: kernel (Red Hat Enterprise Linux 10) - Not affecte
Debian
CVE-2026-23314: linux - In the Linux kernel, the following vulnerability has been resolved: regulator: ...
vendor_debian·2026
CVE-2026-23314 [LOW] CVE-2026-23314: linux - In the Linux kernel, the following vulnerability has been resolved: regulator: ...
In the Linux kernel, the following vulnerability has been resolved: regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio() In bq257xx_reg_dt_parse_gpio(), if fails to get subchild, it returns without calling of_node_put(child), causing the device node reference leak.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.19.8-1)
sid: resolved (fixed in 6.19.8-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
2026-03-25
Published