CVE-2026-23387
published 2026-03-25CVE-2026-23387: In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_or_reset()…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
devm_add_action_or_reset() already invokes the action on failure,
so the explicit put causes a double-put.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.8-1 (forky) | linux 6.19.8-1 (forky) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 36f91eeffd03f5c52406e0c4e2e0fb040307d00c < 188ba3468cb7c098c62609d82e9fc58d29ead7f4 | 188ba3468cb7c098c62609d82e9fc58d29ead7f4 |
| linux | linux | >= 6.12.60 < 6.12.77 | 6.12.77 |
| linux | linux | >= 6.17.10 < 6.18 | 6.18 |
| linux | linux | >= 6.6.118 < 6.6.130 | 6.6.130 |
| linux | linux | >= 9026f31a520d43cc01eb1c08938fc19efadd78cc < 95b14ecc56881dd9a187e1e84dd0daa88ff22c5d | 95b14ecc56881dd9a187e1e84dd0daa88ff22c5d |
| linux | linux | >= 9b07cdf86a0b90556f5b68a6b20b35833b558df3 < ea07fcfbba4301839db3784f09955d9fa3e98090 | ea07fcfbba4301839db3784f09955d9fa3e98090 |
| linux | linux | >= 9b07cdf86a0b90556f5b68a6b20b35833b558df3 < 1e0465139fd9caee7ffefe285ef7d5f21919e474 | 1e0465139fd9caee7ffefe285ef7d5f21919e474 |
| linux | linux | >= 9b07cdf86a0b90556f5b68a6b20b35833b558df3 < fd5bed798f45eb3a178ad527b43ab92705faaf8a | fd5bed798f45eb3a178ad527b43ab92705faaf8a |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.8-1 | 6.19.8-1 |
| linux | linux_kernel | >= 0 < 6.6.130 | 6.6.130 |
| linux | linux_kernel | >= 6.12.60 < 6.12.77 | 6.12.77 |
| linux | linux_kernel | >= 6.13.0 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.17.10 < 6.18 | 6.18 |
| linux | linux_kernel | >= 6.18.0 < 6.19.7 | 6.19.7 |
| linux | linux_kernel | >= 6.18.1 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.19 < 6.19.7 | 6.19.7 |
| linux | linux_kernel | >= 6.6.118 < 6.6.130 | 6.6.130 |
| linux | linux_kernel | >= 6.7.0 < 6.12.77 | 6.12.77 |
| ubuntu | linux | — | — |
| ubuntu | linux-gcp | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
osv·2026-03-25
CVE-2026-23387 pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
devm_add_action_or_reset() already invokes the action on failure,
so the explicit put causes a double-put.
GHSA
GHSA-q9cp-3qrm-w4v3: In the Linux kernel, the following vulnerability has been resolved:
pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
devm_add_action_
ghsa_unreviewed·2026-03-25
CVE-2026-23387 GHSA-q9cp-3qrm-w4v3: In the Linux kernel, the following vulnerability has been resolved:
pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
devm_add_action_
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
devm_add_action_or_reset() already invokes the action on failure,
so the explicit put causes a double-put.
OSV
CVE-2026-23387: In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_or
osv·2026-03-25
CVE-2026-23387 CVE-2026-23387: In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_or
In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_or_reset() already invokes the action on failure, so the explicit put causes a double-put.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacke
Red Hat
kernel: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
vendor_redhat·2026-03-25
CVE-2026-23387 CWE-1341 kernel: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
kernel: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
devm_add_action_or_reset() already invokes the action on failure,
so the explicit put causes a double-put.
A flaw was found in the Linux kernel, specifically within the `pinctrl` subsystem's `cirrus cs42l43` driver. This flaw involves a 'double-put' error in the `cs42l43_pin_probe()` function, where a resource is incorrectly released twice. This issue arises because the `devm_add_action_or_reset()` function already handles resource cleanup, leading to a redundant release. Exploiting this vulnerability could lead to memory corruption, potentially causing a system crash or denial of servic
Debian
CVE-2026-23387: linux - In the Linux kernel, the following vulnerability has been resolved: pinctrl: ci...
vendor_debian·2026
CVE-2026-23387 [LOW] CVE-2026-23387: linux - In the Linux kernel, the following vulnerability has been resolved: pinctrl: ci...
In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_or_reset() already invokes the action on failure, so the explicit put causes a double-put.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.19.8-1)
sid: resolved (fixed in 6.19.8-1)
trixie: open
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/188ba3468cb7c098c62609d82e9fc58d29ead7f4https://git.kernel.org/stable/c/1e0465139fd9caee7ffefe285ef7d5f21919e474https://git.kernel.org/stable/c/95b14ecc56881dd9a187e1e84dd0daa88ff22c5dhttps://git.kernel.org/stable/c/ea07fcfbba4301839db3784f09955d9fa3e98090https://git.kernel.org/stable/c/fd5bed798f45eb3a178ad527b43ab92705faaf8a
2026-03-25
Published