CVE-2026-31645
בינונית 5.5
תיאור (מקור, אנגלית)
In the Linux kernel, the following vulnerability has been resolved: net: lan966x: fix page pool leak in error paths lan966x_fdma_rx_alloc() creates a page pool but does not destroy it if the subsequent fdma_alloc_coherent() call fails, leaking the pool. Similarly, lan966x_fdma_init() frees the coherent DMA memory when lan966x_fdma_tx_alloc() fails but does not destroy the page pool that was successfully created by lan966x_fdma_rx_alloc(), leaking it. Add the missing page_pool_destroy() calls in both error paths.
מדדים
- CVSS 3.1
-
5.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-26/9/2026
- CWE
- CWE-401
מוצרים מושפעים
linux: linux kernel
קישורים
- https://git.kernel.org/stable/c/076344a6ad9d1308faaed1402fdcfdda68b604ab Patch
- https://git.kernel.org/stable/c/22e1ee9f22b5c3bb702bb6d4167d770002a85b2b Patch
- https://git.kernel.org/stable/c/4941e234cfd67ac911fb259642b453f9f76aac41 Patch
- https://git.kernel.org/stable/c/73e940c4249dc5ec6422d1fae535d192fb125955 Patch