CVE-2026-23260

Source
https://cve.org/CVERecord?id=CVE-2026-23260
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23260.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23260
Downstream
Published
2026-03-18T17:41:06.738Z
Modified
2026-03-20T12:47:29.236705Z
Summary
regmap: maple: free entry on mas_store_gfp() failure
Details

In the Linux kernel, the following vulnerability has been resolved:

regmap: maple: free entry on masstoregfp() failure

regcachemaplewrite() allocates a new block ('entry') to merge adjacent ranges and then stores it with masstoregfp(). When masstoregfp() fails, the new 'entry' remains allocated and is never freed, leaking memory.

Free 'entry' on the failure path; on success continue freeing the replaced neighbor blocks ('lower', 'upper').

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23260.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f033c26de5a5734625d2dd1dc196745fae186f1b
Fixed
d61171cf097156030142643942c217759a9cc806
Fixed
811b45e2d795d955bb7fd9c816b40036f4fde350
Fixed
f08f2d2907675926ac5657b25f86d921f269602a
Fixed
f3f380ce6b3d5c9805c7e0b3d5bc28d9ec41e2e8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23260.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.4.0
Fixed
6.6.124
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.70
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23260.json"