CVE-2026-93126

high

Description

In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_q6v5_adsp: Fix reference leak for device node When calling of_parse_phandle_with_args(), the caller is responsible to call of_node_put() to release the reference of device node. In adsp_map_carveout, it does not release the reference.

References

https://git.kernel.org/stable/c/b8bf07b031b202a93d8aa44a4a230a0bbfe0c1fc

https://git.kernel.org/stable/c/a73cfa80f1ec6b0f948cf3c91455c62423747b3e

https://git.kernel.org/stable/c/8c952807c2cebd5e9e9b37146c9383229794c129

https://git.kernel.org/stable/c/7420aac8b1f7e5a75a9d659be3f151dd89de6911

https://git.kernel.org/stable/c/5aed51501447ebb925b0ce0d7d923a9d5ce0bf9e

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.002