CVE-2026-93126

Source
https://cve.org/CVERecord?id=CVE-2026-93126
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93126.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93126
Downstream
Published
2026-09-17T16:11:30Z
Modified
2026-09-19T03:47:27Z
Summary
remoteproc: qcom_q6v5_adsp: Fix reference leak for device node
Details

In the Linux kernel, the following vulnerability has been resolved:

remoteproc: qcom_q6v5_adsp: Fix reference leak for device node

When calling of_parse_phandle_with_args(), the caller is responsible to call of_node_put() to release the reference of device node. In adsp_map_carveout, it does not release the reference.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93126.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f22eedff28aff912bde7f8deabebd121cb64fae3
Fixed
a73cfa80f1ec6b0f948cf3c91455c62423747b3e
Fixed
b8bf07b031b202a93d8aa44a4a230a0bbfe0c1fc
Fixed
7420aac8b1f7e5a75a9d659be3f151dd89de6911
Fixed
5aed51501447ebb925b0ce0d7d923a9d5ce0bf9e
Fixed
8c952807c2cebd5e9e9b37146c9383229794c129

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93126.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.3.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93126.json"