CVE-2026-23132

MEDIUM

Linux Kernel - Resource Leak and Error Handling Flaws in dw_dp_bind

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: synopsys: dw-dp: fix error paths of dw_dp_bind Fix several issues in dw_dp_bind() error handling: 1. Missing return after drm_bridge_attach() failure - the function continued execution instead of returning an error. 2. Resource leak: drm_dp_aux_register() is not a devm function, so drm_dp_aux_unregister() must be called on all error paths after aux registration succeeds. This affects errors from: - drm_bridge_attach() - phy_init() - devm_add_action_or_reset() - platform_get_irq() - devm_request_threaded_irq() 3. Bug fix: platform_get_irq() returns the IRQ number or a negative error code, but the error path was returning ERR_PTR(ret) instead of ERR_PTR(dp->irq). Use a goto label for cleanup to ensure consistent error handling.

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 5.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (9)
linux/Kernel 6.18.0 - 6.18.8linux
Linux/Linux < 6.18
Linux/Linux 6.18
Linux/Linux 6.18.8 - 6.18.*
Linux/Linux 6.19
Linux/Linux 86eecc3a9c2e06462f6a273fcd24150b6da787de - 1a0f69e3c28477b97d3609569b7e8feb4b6162e8
Linux/Linux 86eecc3a9c2e06462f6a273fcd24150b6da787de - 569ed6a73e927a34cae4ae6de1464c0737a5ec44
linux/linux_kernel 6.19 rc1 (6 CPE variants)
linux/linux_kernel 6.18 - 6.18.8
Published Feb 14, 2026
Tracked Since Feb 18, 2026