CVE-2026-23145

MEDIUM

Linux kernel - Use After Free

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ext4: fix iloc.bh leak in ext4_xattr_inode_update_ref The error branch for ext4_xattr_inode_update_ref forget to release the refcount for iloc.bh. Find this when review code.

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 4.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-401
Status published
Products (26)
linux/Kernel < 5.10.249linux
linux/Kernel 5.11.0 - 5.15.199linux
linux/Kernel 5.16.0 - 6.1.162linux
linux/Kernel 6.13.0 - 6.18.7linux
linux/Kernel 6.2.0 - 6.6.122linux
linux/Kernel 6.7.0 - 6.12.67linux
Linux/Linux < 6.18
Linux/Linux 1cfb3e4ddbdc8e02e637b8852540bd4718bf4814 - 7c9f059c3d531a12d7ad96cd34a44b8af7c00d5f
Linux/Linux 3d6269028246f4484bfed403c947a114bb583631 - 3b00c16e42428a1ecd3a5eb9cc37f8ad9bd47626
Linux/Linux 440b003f449a4ff2a00b08c8eab9ba5cd28f3943
... and 16 more
Published Feb 14, 2026
Tracked Since Feb 18, 2026