CVE-2026-23137Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: of: unittest: Fix memory leak in unittest_data_add() In unittest_data_add(), if of_resolve_phandles() fails, the allocated unittest_data is not freed, leading to a memory leak. Fix this by using scope-based cleanup helper __free(kfree) for automatic resource cleanup. This ensures unittest_data is automatically freed when it goes out of scope in error paths. For the success path, use retain_and_null_ptr() to transfer ownership of the memory to the device tree and prevent double freeing.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Patch: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-14: 1Mentions · 2026-10-02: 1Technical Details · 2026-02-14: 102-1410-02
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Patch

    CVE-2026-23137 In the Linux kernel, the following vulnerability has been resolved: of: unittest: Fix memory leak in unittest_data_add() In unittest_data_add(), if of_resolve_phand… https://www.cve.org/CVERecord?id=CVE-2026-23137

    Post summary

    CVE-2026-23137, a memory leak in the Linux kernel’s unittest_data_add(), has been fixed; no exploitation or PoC is reported.

    00010102
    56.4K followersView on X
  • Hero.S@aka_ssy

    Debian’s Giant Kernel CVE List Has No Risk Map If you maintain a Debian stable machine, the actionable part is refreshingly short: upgrade the Linux package to 6.12.111-1. Debian says that release fixes a large batch of kernel vulnerabilities capable of causing privilege escalation, denial of service, or information disclosure. Everything after that gets murkier. The advisory dated September 29, 2026 includes identifiers from 2024, 2025, and 2026, among them CVE-2024-52560, CVE-2025-21817, CVE-2026-23137, and CVE-2026-43198. It also contains a long run of CVE-2026-8xxxx and 9xxxx entries. But the supplied list is cut off, and the notice does not explain each bug’s mechanics, severity, prerequisites, or exact affected configurations. That makes the sheer CVE count a pretty lousy risk meter. Kernel vulnerabilities are not one interchangeable blob: a privilege-escalation bug may require an attacker to already have local access, while a denial-of-service flaw may depend on a particular subsystem being enabled or reachable. An information leak can likewise range from narrowly constrained to genuinely ugly. The advisory’s three broad impact categories tell administrators what could go wrong, but not which machines face which path. The mixed CVE years are easy to overread too. An identifier is not a severity score, nor does its year alone explain when a bug reached Debian, when a fix became available, or how long a specific stable installation was exposed. The announcement does not provide enough chronology to make those judgments. Even the attached PGP signature, which uses SHA-512, solves a different problem. Given a trusted signing key, it helps establish that the message is authentic and unmodified. It does not turn the CVE list into a prioritization guide. So this is a patch-first, investigate-in-parallel advisory. Most trixie users have a clear destination version and little reason to wait for every CVE to receive a readable postmortem. Operators who cannot update immediately have the harder job: checking Debian’s Security Tracker for the affected subsystems and conditions relevant to their systems. The bulletin supplies the fix; the tracker still has to supply the risk map.

    00000103
    3.8K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--

Explore more