VDB

DEBIAN-CVE-2026-23090

DEBIAN-CVE-2026-23090 PUBLISHED CVSS 5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: slimbus: core: fix device reference leak on report present Slimbus devices can be allocated dynamically upon reception of report-present messages. Make sure to drop the reference taken when looking up already registered devices. Note that this requires taking an extra reference in case the device has not yet been registered and has to be allocated.

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:13linux6.12.48-1, 6.12.38-1, 6.12.41-1
Debian:11linux-6.1*, *, 6.1.159-1
Debian:12linux6.1.129-1, 6.1.133-1, 6.1.135-1
Debian:14linux6.18, 6.18, 6.18
Debian:11linux5.10.216-1, 5.10.218-1, 5.10.221-1

Timeline

  • Feb 4, 2026 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›