{"id":"CVE-2026-23137","title":"of: unittest: Fix memory leak in unittest_data_add()","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nof: unittest: Fix memory leak in unittest_data_add()\n\nIn unittest_data_add(), if of_resolve_phandles() fails, the allocated\nunittest_data is not freed, leading to a mem…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 2eb46da2a760e5764c48b752a5ef320e02b96b21 < 58baf98d1bdab897fd796f39a16061bade229d71","Linux >= 2eb46da2a760e5764c48b752a5ef320e02b96b21 < f09b0f705bd7197863b90256ef533a6414d1db2c","Linux >= 2eb46da2a760e5764c48b752a5ef320e02b96b21 < 235a1eb8d2dcc49a6cf0a5ee1aa85544a5d0054b","Linux 3.18"],"published":"2026-02-14","updated":"2026-09-14","sourceUpdated":"2026-09-14T11:58:10.749Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-23137","references":[{"url":"https://git.kernel.org/stable/c/58baf98d1bdab897fd796f39a16061bade229d71"},{"url":"https://git.kernel.org/stable/c/f09b0f705bd7197863b90256ef533a6414d1db2c"},{"url":"https://git.kernel.org/stable/c/235a1eb8d2dcc49a6cf0a5ee1aa85544a5d0054b"}],"tags":["cve.org"],"epss":0.00125,"epssPercentile":0.02578,"ingestedAt":"2026-09-14T15:23:07.459Z","slug":"CVE-2026-23137","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nof: unittest: Fix memory leak in unittest_data_add()\n\nIn unittest_data_add(), if of_resolve_phandles() fails, the allocated\nunittest_data is not freed, leading to a memory leak.\n\nFix this by using scope-based cleanup helper __free(kfree) for automatic\nresource cleanup. This ensures unittest_data is automatically freed when\nit goes out of scope in error paths.\n\nFor the success path, use retain_and_null_ptr() to transfer ownership\nof the memory to the device tree and prevent double freeing.\n\n## Affected\n\n- `Linux >= 2eb46da2a760e5764c48b752a5ef320e02b96b21 < 58baf98d1bdab897fd796f39a16061bade229d71`\n- `Linux >= 2eb46da2a760e5764c48b752a5ef320e02b96b21 < f09b0f705bd7197863b90256ef533a6414d1db2c`\n- `Linux >= 2eb46da2a760e5764c48b752a5ef320e02b96b21 < 235a1eb8d2dcc49a6cf0a5ee1aa85544a5d0054b`\n- `Linux 3.18`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}