Description
In the Linux kernel, the following vulnerability has been resolved:

reset: sunxi: fix memory region leak on ioremap failure

In sunxi_reset_init(), when ioremap() fails, the memory region obtained
via request_mem_region() is not released, leading to a resource leak.

Add an err_mem_region label to properly release the memory region before
freeing the data structure.
Published: 2026-08-15
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Sunxi reset component in the Linux kernel fails to release a memory region when ioremap() fails, creating a resource leak. If an attacker can repeatedly trigger ioremap failures—by influencing the reset process or hardware configuration—they could exhaust kernel memory or cause stability issues, resulting in a denial of service. The core weakness is a missing resource deallocation, which jeopardizes integrity and system availability. This flaw does not directly provide remote code execution or privilege escalation but can serve as a vector for DoS attacks at the kernel level.

Affected Systems

All Linux kernel builds that include the Sunxi reset code are affected. No specific kernel versions or patch levels are listed, so the vulnerability may exist in any unpatched release using this code.

Risk and Exploitability

No CVSS or EPSS score is supplied, and the vulnerability is not listed in CISA KEV, indicating limited public exploitation visibility. The likely attack vector is local; an attacker with access to the device's reset process could induce ioremap failures. Consequently, the risk is Moderate to High for systems that rely on Sunxi hardware and where an attacker can influence reset events. The absence of an exploit path in the public domain does not eliminate the potential for local denial‑of‑service attacks via resource exhaustion.

Generated by OpenCVE AI on August 15, 2026 at 21:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that contains the fix referenced in the commit history
  • Recompile the Sunxi reset module with the updated err_mem_region code from the provided commits if using a custom kernel
  • Monitor system logs for any memory region allocation failures and enforce resource limits to prevent exhaustion in environments where the kernel cannot be updated immediately

Generated by OpenCVE AI on August 15, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: reset: sunxi: fix memory region leak on ioremap failure In sunxi_reset_init(), when ioremap() fails, the memory region obtained via request_mem_region() is not released, leading to a resource leak. Add an err_mem_region label to properly release the memory region before freeing the data structure.
Title reset: sunxi: fix memory region leak on ioremap failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:51:31.551Z

Reserved: 2026-07-30T09:28:09.396Z

Link: CVE-2026-68475

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:20:35.067

Modified: 2026-08-15T06:20:35.067

Link: CVE-2026-68475

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T21:15:03Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime