Executive brief
A memory leak vulnerability was identified in the Texas Instruments K3 SoC information driver within the Linux kernel. This component is responsible for identifying hardware revision details on specific TI processors. If the driver fails to initialize properly, it fails to release allocated memory, which could eventually lead to system instability or a denial-of-service condition if triggered repeatedly.
Technical details
A memory leak exists in drivers/soc/ti/k3-socinfo.c due to the use of regmap_init_mmio() without a corresponding free operation during probe failures or driver unbinding. Specifically, when the k3_chipinfo_probe function encounters an error (such as probe deferral), the allocated mmio regmap is never released. This is a CWE-401 'Missing Release of Memory after Effective Lifetime' vulnerability. An attacker with local access could potentially trigger repeated probe attempts to exhaust system memory. The fix involves switching to the device-managed allocator devm_regmap_init_mmio(), which ensures automatic resource cleanup.
Affected products
- Linux Linux Kernel 5.10.238 to 5.10.252, 5.15.185 to 5.15.202, 6.1.141 to 6.1.165, 6.6.93 to 6.6.128, 6.12.31 to 6.12.75, 6.14.9 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2025-11-27: other: Patch authored
- 2026-05-06: disclosed: CVE published
- 2026-05-11: advisory: NVD analysis completed
References
- https://git.kernel.org/stable/c/458136527fe127fd051c1c9537f4540849780d70
- https://git.kernel.org/stable/c/ab1ac24c407e4df326d7154a4deadd444e9209d9
- https://git.kernel.org/stable/c/b1006b5892ec8a95d039a89b47e6fd69cf607405
- https://git.kernel.org/stable/c/bbaa9e615608c204d384a7d4b1a434580a142d4c
- https://git.kernel.org/stable/c/c933138d45176780fabbbe7da263e04d5b3e525d
- https://git.kernel.org/stable/c/c97c21d342838b2a7787b0f1d6ad417e85c906f6
- https://git.kernel.org/stable/c/d451bf970a0c54b586f8b3161261bdf35d463c99