#VU124945 Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-23426
Published: April 6, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a device node reference leak in logicvc_drm_config_parse() when parsing the "layers" node from the device tree. A local user can trigger the vulnerable code path to cause a denial of service.
The issue results from a missing release of the reference returned by of_get_child_by_name(). No user interaction is required.
Remediation
External links
- https://git.kernel.org/stable/c/0bd326dffd9e103335d77d9c31275c0d5a7979eb
- https://git.kernel.org/stable/c/78e91e49d28e05ccaa6b445bafb5e367d57c9583
- https://git.kernel.org/stable/c/871630255ecd2d9b64ad1d75a7dfc0567d7d9989
- https://git.kernel.org/stable/c/b88f49910be147b7974098b9172b0d3873142d6a
- https://git.kernel.org/stable/c/f8a6eba20edb938166b26e133cc61306e1bc6de9
- https://git.kernel.org/stable/c/fef0e649f8b42bdffe4a916dd46e1b1e9ad2f207