CVE-2026-23389
Description
In the Linux kernel, the following vulnerability has been resolved:
ice: Fix memory leak in ice_set_ringparam()
In ice_set_ringparam, tx_rings and xdp_rings are allocated before rx_rings. If the allocation of rx_rings fails, the code jumps to the done label leaking both tx_rings and xdp_rings. Furthermore, if the setup of an individual Rx ring fails during the loop, the code jumps to the free_tx label which releases tx_rings but leaks xdp_rings.
Fix this by introducing a free_xdp label and updating the error paths to ensure both xdp_rings and tx_rings are properly freed if rx_rings allocation or setup fails.
Compile tested only. Issue found using a prototype static analysis tool and code review.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=4.17.1,<6.12.81
- cpe:2.3:o:linux:linux_kernel:4.17:-:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
6- git.kernel.org/stable/c/44ba32a892b72de3faa04b8cfb1f2f1418fdd580nvdPatch
- git.kernel.org/stable/c/63dc317dfcd3faffd082c2bf3080f9ad070273danvdPatch
- git.kernel.org/stable/c/b23282218eca27b710111460b4964c8a456c6c44nvdPatch
- git.kernel.org/stable/c/fe868b499d16f55bbeea89992edb98043c9de416nvdPatch
- git.kernel.org/stable/c/bddf04e3822e4fa38691433dd0750420d49a0dd6nvd
- git.kernel.org/stable/c/e0c211a0c26159058303712d6b4fbd1c88835e6dnvd
News mentions
0No linked articles in our index yet.