Boletines de Vulnerabilidades

CVE-2026-23337

   
Software afectado LINUX KERNEL
 
In the Linux kernel, the following vulnerability has been resolved:

pinctrl: pinconf-generic: Fix memory leak in pinconf_generic_parse_dt_config()

In pinconf_generic_parse_dt_config(), if parse_dt_cfg() fails, it returns
directly. This bypasses the cleanup logic and results in a memory leak of
the cfg buffer.

Fix this by jumping to the out label on failure, ensuring kfree(cfg) is
called before returning.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-23337