In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Release VFCT ACPI table reference
amdgpuacpivfctbios() fetches the VFCT table with acpigettable() but never releases it. acpigettable() takes a reference on the table (incrementing its validationcount and mapping it on the 0->1 transition); without a paired acpiputtable() the mapping is leaked on every call, whether or not a matching VBIOS image is found.
Route all exit paths after the table is acquired through a common acpiputtable(). The VBIOS image is copied out with kmemdup() before the table is released, so it remains valid for the caller.
(cherry picked from commit ca5988682b4cba4cd125a0fa99b2de1239164ae4)
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68238.json",
"cna_assigner": "Linux"
}