Boletines de Vulnerabilidades

CVE-2026-23123

   
Software afectado LINUX KERNEL
 
In the Linux kernel, the following vulnerability has been resolved:

interconnect: debugfs: initialize src_node and dst_node to empty strings

The debugfs_create_str() API assumes that the string pointer is either NULL
or points to valid kmalloc() memory. Leaving the pointer uninitialized can
cause problems.

Initialize src_node and dst_node to empty strings before creating the
debugfs entries to guarantee that reads and writes are safe.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-23123