CVE-2026-93126
Published: September 19, 2026Last modified: September 19, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_q6v5_adsp: Fix reference leak for device node When calling of_parse_phandle_with_args(), the caller is responsible to call of_node_put() to release the reference of device node. In adsp_map_carveout, it does not release the reference.
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Not affected (6.1.33-r0) |
| 25 LTS | linux-lts | Vulnerable (6.12.103-r0) | |
| Stream | linux-lts | Vulnerable (6.18.46-r0) |
References
- https://git.kernel.org/stable/c/5aed51501447ebb925b0ce0d7d923a9d5ce0bf9e
- https://git.kernel.org/stable/c/7420aac8b1f7e5a75a9d659be3f151dd89de6911
- https://git.kernel.org/stable/c/8c952807c2cebd5e9e9b37146c9383229794c129
- https://git.kernel.org/stable/c/a73cfa80f1ec6b0f948cf3c91455c62423747b3e
- https://git.kernel.org/stable/c/b8bf07b031b202a93d8aa44a4a230a0bbfe0c1fc