CVE-2026-23426: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: drm/logicvc: Fix device node reference leak in logicvc_drm_config_parse() The logicvc_drm_config_parse() function calls of_get_child_by_name() to find the "layers" node but fails to release the reference, leading to a device node reference leak. Fix this by using the __free(device_node) cleanup attribute to automatic release the reference when the variable goes out of scope.
Affected products
- Linux Linux Kernel: from 6.0.1, before 6.1.167 (fixed in 6.1.167); from 6.2, before 6.6.130 (fixed in 6.6.130); from 6.7, before 6.12.77 (fixed in 6.12.77); from 6.13, before 6.18.17 (fixed in 6.18.17); from 6.19, before 6.19.7 (fixed in 6.19.7); version 6.0 only; …
Published 2026-04-03. Last modified 2026-07-24.