CVE-2026-23090

MEDIUM

Linux Kernel - Use-After-Free in Slimbus Core Report Present Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: slimbus: core: fix device reference leak on report present Slimbus devices can be allocated dynamically upon reception of report-present messages. Make sure to drop the reference taken when looking up already registered devices. Note that this requires taking an extra reference in case the device has not yet been registered and has to be allocated.

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 4.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (24)
linux/Kernel 4.16.0 - 5.10.249linux
linux/Kernel 5.11.0 - 5.15.199linux
linux/Kernel 5.16.0 - 6.1.162linux
linux/Kernel 6.13.0 - 6.18.8linux
linux/Kernel 6.2.0 - 6.6.122linux
linux/Kernel 6.7.0 - 6.12.68linux
Linux/Linux < 4.16
Linux/Linux 4.16
Linux/Linux 46a2bb5a7f7ea2728be50f8f5b29a20267f700fe - 02b78bbfbafe49832e508079148cb87cdfa55825
Linux/Linux 46a2bb5a7f7ea2728be50f8f5b29a20267f700fe - 2ddc09f6a0a221b1d91a7cbc8cc2cefdbd334fe6
... and 14 more
Published Feb 04, 2026
Tracked Since Feb 18, 2026