PT-2026-5524 · Linux+2 · Linux Kernel+2

Published

2026-01-01

·

Updated

2026-06-04

·

CVE-2026-23021

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak exists in the update eth regs async() function when asynchronously writing to device registers. If usb submit urb() fails, resources allocated up to that point are not released, leading to a memory leak.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

BDU:2026-04096
CVE-2026-23021
ECHO-A4D7-CE0F-6800
OESA-2026-1566
OESA-2026-1567
OESA-2026-1570
OPENSUSE-SU-2026:20416-1
SUSE-SU-2026:0962-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21284-1
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8116-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8243-1
USN-8278-1
USN-8278-2
USN-8289-1
USN-8289-2
USN-8296-1
USN-8296-2
USN-8393-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu