Memory leak in Linux kernel - CVE-2026-93126
Published: September 18, 2026
Vulnerability identifier: #VU150878
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93126
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to leak device node references.
The vulnerability exists due to a missing release of a device node reference in the adsp_map_carveout function when calling of_parse_phandle_with_args(). A local user can cause the function to process a device-tree phandle to leak device node references.
Affected software
Linux kernel
How to mitigate CVE-2026-93126
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/5aed51501447ebb925b0ce0d7d923a9d5ce0bf9e
- https://git.kernel.org/stable/c/7420aac8b1f7e5a75a9d659be3f151dd89de6911
- https://git.kernel.org/stable/c/8c952807c2cebd5e9e9b37146c9383229794c129
- https://git.kernel.org/stable/c/a73cfa80f1ec6b0f948cf3c91455c62423747b3e
- https://git.kernel.org/stable/c/b8bf07b031b202a93d8aa44a4a230a0bbfe0c1fc