CVE-2026-23314

MEDIUM

regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio()

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio() In bq257xx_reg_dt_parse_gpio(), if fails to get subchild, it returns without calling of_node_put(child), causing the device node reference leak.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 3.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (14)
linux/Kernel 6.18.0 - 6.18.17linux
linux/Kernel 6.19.0 - 6.19.7linux
Linux/Linux < 6.18
Linux/Linux 6.18
Linux/Linux 6.18.17 - 6.18.*
Linux/Linux 6.19.7 - 6.19.*
Linux/Linux 7.0
Linux/Linux 7.0-rc2
Linux/Linux 981dd162b63578aee34b5c68795e246734b76d70 - 4baaddaa44af01cd4ce239493060738fd0881835
Linux/Linux 981dd162b63578aee34b5c68795e246734b76d70 - 93b64bef8cd4074806d981ed1b4c38c3ae0542e3
... and 4 more
Published Mar 25, 2026
Tracked Since Mar 25, 2026