CVE-2026-23090: slimbus: core: fix device reference leak on report present
In the Linux kernel, the following vulnerability has been resolved:
slimbus: core: fix device reference leak on report present
Slimbus devices can be allocated dynamically upon reception of report-present messages.
Make sure to drop the reference taken when looking up already registered devices.
Note that this requires taking an extra reference in case the device has not yet been registered and has to be allocated.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23090?
The severity of CVE-2026-23090 is classified as medium with a CVSS score of 5.5.
How do I fix CVE-2026-23090?
You can fix CVE-2026-23090 by applying the available patch provided by the Linux kernel.
What does CVE-2026-23090 affect?
CVE-2026-23090 affects the Linux kernel, specifically the Slimbus core functionality.
What is the risk associated with CVE-2026-23090?
CVE-2026-23090 has a risk rating of 24, indicating a notable potential threat.
When was CVE-2026-23090 published?
CVE-2026-23090 was published on February 4, 2026.