CVE-2026-53213: drm/vc4: fix krealloc() memory leak
Published Jun 25, 2026
·Updated
drm/vc4: fix krealloc() memory leak
Affected Software
15 affected componentsFixes available
Linux Linux kernel (drm/vc4)
Microsoft azl3 kernel 6.6.141.1-1<6.6.143.1-1
6.6.143.1-1
Linux Linux kernel>=4.8<5.15.210
Linux Linux kernel>=5.16<6.1.176
Linux Linux kernel>=6.2<6.6.143
Linux Linux kernel>=6.7<6.12.94
Linux Linux kernel>=6.13<6.18.36
Linux Linux kernel>=6.19<7.0.13
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3
Linux Linux kernel=7.1-rc4
Linux Linux kernel=7.1-rc5
Linux Linux kernel=7.1-rc6
Linux Linux kernel=7.1-rc7
Remediation
Event History
Jun 25, 2026
CVE Published
via MITRE·08:39 AM
Data Sourced
via MITRE·08:39 AM
Description
Data Sourced
via NVD·09:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 27, 2026
Data Sourced
via Microsoft·08:06 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:06 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-53213?
The severity of CVE-2026-53213 is medium with a score of 5.5.
2
How does CVE-2026-53213 affect Linux kernel users?
CVE-2026-53213 can lead to a memory leak in the Linux kernel's drm/vc4 component.
3
What is the recommended fix for CVE-2026-53213?
The recommended fix for CVE-2026-53213 involves checking the return value of krealloc() before overwriting the original pointer.
4
Is CVE-2026-53213 exploitable remotely?
CVE-2026-53213 is not considered remotely exploitable as it affects local kernel memory management.
5
What systems are impacted by CVE-2026-53213?
CVE-2026-53213 impacts systems running affected versions of the Linux kernel that utilize the drm/vc4 component.