Back to overview

CVE-2026-53213

Description
In the Linux kernel, the following vulnerability has been resolved: drm/vc4: fix krealloc() memory leak Don't just overwrite the original pointer passed to krealloc() with its return value without checking latter: MEM = krealloc(MEM, SZ, GFP); If krealloc() returns NULL, that erases the pointer to the still allocated memory, hence leaks this memory. Instead, use a temporary variable, check it's not NULL and only then assign it to the original pointer: TMP = krealloc(MEM, SZ, GFP); if (!TMP) return; MEM = TMP; While on it, use krealloc_array().

Metadata

CVE ID
CVE-2026-53213
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-25 08:39 UTC
Last updated
2026-06-25 08:39 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 6d45c81d229d71da54d374143e7d6abad4c0cf31 < 30165a09f76eaf34951c818eb5d9d6e4771d76f6, 6d45c81d229d71da54d374143e7d6abad4c0cf31 < fd87d6966041e33ef7d2e5dc59f9a52b71c6ae5f, 6d45c81d229d71da54d374143e7d6abad4c0cf31 < e0ce103e89d61eef70edc1d1ae3bfd4c0aacbc2e, 6d45c81d229d71da54d374143e7d6abad4c0cf31 < c034aa0b1ba5f49cbdf8ef193d6ec714d74aac27 …
Linux Linux 4.8, 0 < 4.8, 5.15.210 ≤ 5.15.*, 6.1.176 ≤ 6.1.* …
Back to overview