CVE-2026-23431

Source
https://cve.org/CVERecord?id=CVE-2026-23431
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23431.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23431
Downstream
Published
2026-04-03T15:15:17.355Z
Modified
2026-07-27T03:56:22.991051607Z
Summary
spi: amlogic-spisg: Fix memory leak in aml_spisg_probe()
Details

In the Linux kernel, the following vulnerability has been resolved:

spi: amlogic-spisg: Fix memory leak in amlspisgprobe()

In amlspisgprobe(), ctlr is allocated by spialloctarget()/spiallochost(), but fails to call spicontrollerput() in several error paths. This leads to a memory leak whenever the driver fails to probe after the initial allocation.

Convert to use devmspiallochost()/devmspialloctarget() to fix the memory leak.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23431.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cef9991e04aed3305c61c392e880f6e01a0c2ea4
Fixed
bec21d97c968a4806939eb2946df49ea6c341bde
Fixed
8e28a01b69f7ea8df7ceb15470cfe643b2828f4f
Fixed
b8db9552997924b750e727a625a30eaa4603bbb9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23431.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.17.0
Fixed
6.18.20
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23431.json"