CVE-2026-23022

MEDIUM

Linux Kernel - Memory Leak

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leak in idpf_vc_core_deinit() Make sure to free hw->lan_regs. Reported by kmemleak during reset: unreferenced object 0xff1b913d02a936c0 (size 96): comm "kworker/u258:14", pid 2174, jiffies 4294958305 hex dump (first 32 bytes): 00 00 00 c0 a8 ba 2d ff 00 00 00 00 00 00 00 00 ......-......... 00 00 40 08 00 00 00 00 00 00 25 b3 a8 ba 2d ff ..@.......%...-. backtrace (crc 36063c4f): __kmalloc_noprof+0x48f/0x890 idpf_vc_core_init+0x6ce/0x9b0 [idpf] idpf_vc_event_task+0x1fb/0x350 [idpf] process_one_work+0x226/0x6d0 worker_thread+0x19e/0x340 kthread+0x10f/0x250 ret_from_fork+0x251/0x2b0 ret_from_fork_asm+0x1a/0x30

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 5.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-401
Status published
Products (10)
linux/Kernel 6.17.0 - 6.18.6linux
Linux/Linux < 6.17
Linux/Linux 6.17
Linux/Linux 6.18.6 - 6.18.*
Linux/Linux 6.19
Linux/Linux 6aa53e861c1a0c042690c9b7c5c153088ae61079 - 23391db8a00c23854915b8b72ec1aa10080aa540
Linux/Linux 6aa53e861c1a0c042690c9b7c5c153088ae61079 - e111cbc4adf9f9974eed040aeece7e17460f6bff
linux/linux_kernel 6.17
linux/linux_kernel 6.19 rc1 (8 CPE variants)
linux/linux_kernel 6.17.1 - 6.18.6
Published Jan 31, 2026
Tracked Since Feb 18, 2026