CVE-2026-23421

In the Linux kernel, the following vulnerability has been resolved: drm/xe/configfs: Free ctx_restore_mid_bb in release ctx_restore_mid_bb memory is allocated in wa_bb_store(), but xe_config_device_release() only frees ctx_restore_post_bb. Free ctx_restore_mid_bb[0].cs as well to avoid leaking the allocation when the configfs device is removed. (cherry picked from commit a235e7d0098337c3f2d1e8f3610c719a589e115f)
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.18:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: drm/xe/configfs: Liberar ctx_restore_mid_bb en la liberación La memoria de ctx_restore_mid_bb se asigna en wa_bb_store(), pero xe_config_device_release() solo libera ctx_restore_post_bb. Liberar ctx_restore_mid_bb[0].cs también para evitar la fuga de la asignación cuando se elimina el dispositivo configfs. (extraído del commit a235e7d0098337c3f2d1e8f3610c719a589e115f)

24 Apr 2026, 15:21

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/3557359ea3df32430ea7c30f7a708ca9a91d7e0e - () https://git.kernel.org/stable/c/3557359ea3df32430ea7c30f7a708ca9a91d7e0e - Patch
References () https://git.kernel.org/stable/c/7f971dfd48983074adc7bbcea3ee95ce7aad47cb - () https://git.kernel.org/stable/c/7f971dfd48983074adc7bbcea3ee95ce7aad47cb - Patch
References () https://git.kernel.org/stable/c/e377182f0266f46f02d01838e6bde67b9dac0d66 - () https://git.kernel.org/stable/c/e377182f0266f46f02d01838e6bde67b9dac0d66 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux
Linux linux Kernel
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.18:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*

03 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 14:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-23421

Mitre link : CVE-2026-23421

CVE.ORG link : CVE-2026-23421


JSON object : View

Products Affected

linux

  • linux_kernel