CVE-2026-97440

Summary

In the Linux kernel, the following vulnerability has been resolved:

net: qrtr: fix node refcount leak on ctrl packet alloc failure

qrtr_send_resume_tx() calls qrtr_node_lookup() which takes a reference on the returned node. If the subsequent call to qrtr_alloc_ctrl_packet() fails due to memory allocation failure, the function returns -ENOMEM without calling qrtr_node_release() to release the node reference.

Add qrtr_node_release(node) before returning on the allocation failure path to properly release the reference.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxcb6530b99fafea6c0636c4640bd21301d12cdbc9 < 477353db343663d5502ca442c6de785d2f23f273affected
LinuxLinuxcb6530b99fafea6c0636c4640bd21301d12cdbc9 < 9d969c98732a4d42212ec580dd5bbad53f246103affected
LinuxLinuxcb6530b99fafea6c0636c4640bd21301d12cdbc9 < 3b09ff54114566864eea59020f6b69c5bb325b9daffected
LinuxLinux5.6affected
LinuxLinux0 < 5.6unaffected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References