CVE-2026-23028

Linux Kernel 6.13-6.18.6 - Memory Leak in KVM IPI Device Destruction

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix kvm_device leak in kvm_ipi_destroy() In kvm_ioctl_create_device(), kvm_device has allocated memory, kvm_device->destroy() seems to be supposed to free its kvm_device struct, but kvm_ipi_destroy() is not currently doing this, that would lead to a memory leak. So, fix it.

Scores

EPSS 0.0001
EPSS Percentile 1.6%

Details

Status published
Products (7)
linux/Kernel 6.13.0 - 6.18.7linux
Linux/Linux < 6.13
Linux/Linux 6.13
Linux/Linux 6.18.7 - 6.18.*
Linux/Linux 6.19
Linux/Linux c532de5a67a70f8533d495f8f2aaa9a0491c3ad0 - 0bf58cb7288a4d3de6d8ecbb3a65928a9362bf21
Linux/Linux c532de5a67a70f8533d495f8f2aaa9a0491c3ad0 - 5defcc2f9c22e6e09b5be68234ad10f4ba0292b7
Published Jan 31, 2026
Tracked Since Feb 18, 2026