Junglewise Threat Intelligence

CVE-2026-23033: Linux Kernel resource leak in OMAP DMA engine driver

CVE-2026-23033 · Severity: info · CVSS 2.1 · Published 2026-01-31

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A resource leak was identified in the Linux kernel's OMAP DMA engine driver. When the driver fails to initialize properly, it fails to release certain memory resources, which could lead to a gradual depletion of system memory if the failure occurs repeatedly. This primarily affects system stability and availability rather than data security.

Technical details

A resource leak exists in the omap-dma driver (drivers/dma/ti/omap-dma.c) within the Linux kernel. The vulnerability occurs during the driver's probe sequence: if dma_async_device_register() or of_dma_controller_register() fails, the dma_pool created via dma_pool_create() is not destroyed. This results in a memory leak in the error handling paths. An attacker with local access could potentially trigger these error paths to cause memory exhaustion, though the practical impact is limited to denial of service. The issue has been resolved by adding dma_pool_destroy() calls to the affected error paths.

Affected products

  • Linux Linux Kernel All versions prior to the fix in early 2026

Timeline

  • 2025-11-03: other: Vulnerability reported by Haotian Zhang
  • 2026-01-11: patched: Initial fix committed to mainline kernel
  • 2026-01-31: disclosed: CVE-2026-23033 published

References

Related threats