5.5
CVE-2026-31645
- EPSS 0.12%
- Veröffentlicht 24.04.2026 14:44:58
- Zuletzt bearbeitet 27.04.2026 20:19:07
- Erkennungen
net: lan966x: fix page pool leak in error paths
In the Linux kernel, the following vulnerability has been resolved: net: lan966x: fix page pool leak in error paths lan966x_fdma_rx_alloc() creates a page pool but does not destroy it if the subsequent fdma_alloc_coherent() call fails, leaking the pool. Similarly, lan966x_fdma_init() frees the coherent DMA memory when lan966x_fdma_tx_alloc() fails but does not destroy the page pool that was successfully created by lan966x_fdma_rx_alloc(), leaking it. Add the missing page_pool_destroy() calls in both error paths.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.2.1 < 6.12.82
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.23
Linux ≫ Linux Kernel Version >= 6.19 < 6.19.13
Linux ≫ Linux Kernel Version 6.2 Update -
Linux ≫ Linux Kernel Version 7.0 Update rc1
Linux ≫ Linux Kernel Version 7.0 Update rc2
Linux ≫ Linux Kernel Version 7.0 Update rc3
Linux ≫ Linux Kernel Version 7.0 Update rc4
Linux ≫ Linux Kernel Version 7.0 Update rc5
Linux ≫ Linux Kernel Version 7.0 Update rc6
Linux ≫ Linux Kernel Version 7.0 Update rc7
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.023 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-401 Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
https://git.kernel.org/stable/c/73e940c4249dc5ec6422d1fae535d192fb125955
https://git.kernel.org/stable/c/22e1ee9f22b5c3bb702bb6d4167d770002a85b2b
https://git.kernel.org/stable/c/4941e234cfd67ac911fb259642b453f9f76aac41
https://git.kernel.org/stable/c/076344a6ad9d1308faaed1402fdcfdda68b604ab