IT

Tracker / CVE-2026-23026

CVE-2026-23026

Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() Fix a memory leak in gpi_peripheral_config() where the original memory pointed to by gchan->config could be lost if krealloc() fails. The issue occurs when: 1. gchan->config points to previously allocated memory 2. krealloc() fails and returns NULL 3. The function directly assigns NULL to gchan->config, losing the reference to the original memory 4. The original memory becomes unreachable and cannot be freed Fix this by using a temporary variable to hold the krealloc() result and only updating gchan->config when the allocation succeeds. Found via static analysis and code review.

Affected products and versions

linux linux_kernel
linux linux_kernel · 5.11.1 → 5.15.199
linux linux_kernel · 5.16 → 6.1.162
linux linux_kernel · 6.13 → 6.18.7
linux linux_kernel · 6.2 → 6.6.122
linux linux_kernel · 6.7 → 6.12.67

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References