---
id: CVE-2026-23026
title: 'dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config()'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config()

  Fix a memory leak in gpi_peripheral_config() where the original memory
  pointed to by gchan->config cou…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 <
    4532f18e4ab36def1f55cd936d0fc002b2ce34c2
  - >-
    Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 <
    694ab1f6f16cb69f7c5ef2452b22ba7b00a3c7c7
  - >-
    Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 <
    6bf4ef078fd11910988889a6c0b3698d2e0c89af
  - >-
    Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 <
    01b1d781394fc9b83015e3a3cd46b17bda842bd8
  - >-
    Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 <
    55a67ba5ac4cebfd54cc8305d4d57a0f1dfe6a85
  - >-
    Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 <
    3f747004bbd641131d9396d87b5d2d3d1e182728
  - Linux 5.11
published: '2026-01-31'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:44:40.750Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-23026'
references:
  - url: 'https://git.kernel.org/stable/c/4532f18e4ab36def1f55cd936d0fc002b2ce34c2'
  - url: 'https://git.kernel.org/stable/c/694ab1f6f16cb69f7c5ef2452b22ba7b00a3c7c7'
  - url: 'https://git.kernel.org/stable/c/6bf4ef078fd11910988889a6c0b3698d2e0c89af'
  - url: 'https://git.kernel.org/stable/c/01b1d781394fc9b83015e3a3cd46b17bda842bd8'
  - url: 'https://git.kernel.org/stable/c/55a67ba5ac4cebfd54cc8305d4d57a0f1dfe6a85'
  - url: 'https://git.kernel.org/stable/c/3f747004bbd641131d9396d87b5d2d3d1e182728'
tags:
  - cve.org
epss: 0.00195
epssPercentile: 0.08136
ingestedAt: '2026-09-08T15:33:26.994Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config()

Fix a memory leak in gpi_peripheral_config() where the original memory
pointed to by gchan->config could be lost if krealloc() fails.

The issue occurs when:
1. gchan->config points to previously allocated memory
2. krealloc() fails and returns NULL
3. The function directly assigns NULL to gchan->config, losing the
   reference to the original memory
4. The original memory becomes unreachable and cannot be freed

Fix this by using a temporary variable to hold the krealloc() result
and only updating gchan->config when the allocation succeeds.

Found via static analysis and code review.

## Affected

- `Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 4532f18e4ab36def1f55cd936d0fc002b2ce34c2`
- `Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 694ab1f6f16cb69f7c5ef2452b22ba7b00a3c7c7`
- `Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 6bf4ef078fd11910988889a6c0b3698d2e0c89af`
- `Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 01b1d781394fc9b83015e3a3cd46b17bda842bd8`
- `Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 55a67ba5ac4cebfd54cc8305d4d57a0f1dfe6a85`
- `Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 3f747004bbd641131d9396d87b5d2d3d1e182728`
- `Linux 5.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
