firmware: stratix10-svc: fix memory leaks and list corruption bugs
Summary
| CVE | CVE-2026-68183 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 13:20:05 UTC |
| Updated | 2026-08-19 17:20:34 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix memory leaks and list corruption bugs Fix a memory leak when gen_pool_alloc() fails by freeing pmem on the error path. Switch pmem allocation from devm_kzalloc() to kzalloc() with explicit kfree() in the free path to match its list-managed lifetime. Remove the erroneous list_del(&svc_data_mem) which corrupted the list head on failed lookups. |
Risk And Classification
EPSS: 0.002000000 probability, percentile 0.101830000 (date 2026-08-19)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 7ca5ce896524f5292e610b27d168269e5ab74951 76cff60d7fcb08da537f529bf32a0927bb17265f git | Not specified |
| CNA | Linux | Linux | affected 7ca5ce896524f5292e610b27d168269e5ab74951 b9206568e08424fd817a4aeca4f944e241d2f530 git | Not specified |
| CNA | Linux | Linux | affected 7ca5ce896524f5292e610b27d168269e5ab74951 5df709d59227994888d7dbb7ea6c83316f0b79c0 git | Not specified |
| CNA | Linux | Linux | affected 7ca5ce896524f5292e610b27d168269e5ab74951 95f702e372964aff486338783f49e28a40a53127 git | Not specified |
| CNA | Linux | Linux | affected 7ca5ce896524f5292e610b27d168269e5ab74951 fff6e5ff0318315998b540896537eaaa2ebf9f7b git | Not specified |
| CNA | Linux | Linux | affected 7ca5ce896524f5292e610b27d168269e5ab74951 4f2db41a09eba7a45abd140bb86ffc519c191886 git | Not specified |
| CNA | Linux | Linux | affected 7ca5ce896524f5292e610b27d168269e5ab74951 8e93a083456d78f6b0aa1f58d2b0c7071a2a7a47 git | Not specified |
| CNA | Linux | Linux | affected 7ca5ce896524f5292e610b27d168269e5ab74951 9119ceb76e987c2ec2b549ea100e3268ce3a1c7c git | Not specified |
| CNA | Linux | Linux | affected 5.0 | Not specified |
| CNA | Linux | Linux | unaffected 5.0 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.265 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.216 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.183 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.151 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.101 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.42 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.6 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/5df709d59227994888d7dbb7ea6c83316f0b79c0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/fff6e5ff0318315998b540896537eaaa2ebf9f7b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/76cff60d7fcb08da537f529bf32a0927bb17265f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8e93a083456d78f6b0aa1f58d2b0c7071a2a7a47 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/95f702e372964aff486338783f49e28a40a53127 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4f2db41a09eba7a45abd140bb86ffc519c191886 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b9206568e08424fd817a4aeca4f944e241d2f530 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9119ceb76e987c2ec2b549ea100e3268ce3a1c7c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.