CVE-2026-23387Multiple Releases of Same Resource or Handle in Linux

Severity
5.3MEDIUM
No vector
EPSS
0.0%
top 93.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25

Description

In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_or_reset() already invokes the action on failure, so the explicit put causes a double-put.

Affected Packages4 packages

Linuxlinux/linux_kernel6.7.06.12.77+3
Debianlinux/linux_kernel< 6.19.8-1
CVEListV5linux/linux9026f31a520d43cc01eb1c08938fc19efadd78cc95b14ecc56881dd9a187e1e84dd0daa88ff22c5d+6
debiandebian/linux< linux 6.19.8-1 (forky)

🔴Vulnerability Details

3
OSV
pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()2026-03-25
GHSA
GHSA-q9cp-3qrm-w4v3: In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_2026-03-25
OSV
CVE-2026-23387: In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_or2026-03-25

📋Vendor Advisories

2
Red Hat
kernel: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()2026-03-25
Debian
CVE-2026-23387: linux - In the Linux kernel, the following vulnerability has been resolved: pinctrl: ci...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23387 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23387 — Linux vulnerability | cvebase