CVE-2026-23337Missing Release of Resource after Effective Lifetime in Linux

Severity
7.2HIGHGHSA
No vector
EPSS
0.0%
top 93.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateApr 1

Description

In the Linux kernel, the following vulnerability has been resolved: pinctrl: pinconf-generic: Fix memory leak in pinconf_generic_parse_dt_config() In pinconf_generic_parse_dt_config(), if parse_dt_cfg() fails, it returns directly. This bypasses the cleanup logic and results in a memory leak of the cfg buffer. Fix this by jumping to the out label on failure, ensuring kfree(cfg) is called before returning.

Affected Packages7 packages

Linuxlinux/linux_kernel6.19.06.19.7
Debianlinux/linux_kernel< 6.19.8-1
CVEListV5linux/linux90a18c512884adb49ddc2fb30e94594169aae80863ee429780a5d43b5b4406c6128109b0f47cf2f1+2
debiandebian/linux< linux 6.19.8-1 (forky)
npmlodash/lodash4.0.04.18.0

🔴Vulnerability Details

4
GHSA
lodash vulnerable to Code Injection via `_.template` imports key names2026-04-01
OSV
CVE-2026-23337: In the Linux kernel, the following vulnerability has been resolved: pinctrl: pinconf-generic: Fix memory leak in pinconf_generic_parse_dt_config() In2026-03-25
OSV
pinctrl: pinconf-generic: Fix memory leak in pinconf_generic_parse_dt_config()2026-03-25
GHSA
GHSA-5599-vj49-3fh3: In the Linux kernel, the following vulnerability has been resolved: pinctrl: pinconf-generic: Fix memory leak in pinconf_generic_parse_dt_config() I2026-03-25

📋Vendor Advisories

3
Red Hat
lodash: lodash: Arbitrary code execution via untrusted input in template imports2026-03-31
Red Hat
kernel: pinctrl: pinconf-generic: Fix memory leak in pinconf_generic_parse_dt_config()2026-03-25
Debian
CVE-2026-23337: linux - In the Linux kernel, the following vulnerability has been resolved: pinctrl: pi...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23337 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-4800 lodash: lodash: Arbitrary code execution via untrusted input in template imports2026-03-31