Description
In the Linux kernel, the following vulnerability has been resolved:

pinctrl: generic: free maps on pinctrl_generic_to_map() failure

pinctrl_generic_to_map() parses DT configuration and allocates pinctrl
maps via pinctrl_utils_reserve_map().

If subsequent steps (such as pinctrl_utils_add_map_mux(),
pinctrl_generic_add_group(), pinconf_generic_parse_dt_config(), or
pinctrl_utils_add_map_configs()) return an error, *maps may contain
partially allocated map entries. Returning the error directly without
freeing *maps leaks the allocated mapping memory across all drivers
that rely on pinctrl_generic_to_map().

Fix this by calling pinctrl_utils_free_map() and resetting *maps,
*num_maps, and *num_reserved_maps in the error path of
pinctrl_generic_to_map().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak leading to Resource Exhaustion
Action: Patch Kernel
AI Analysis

Impact

The vulnerable function pinctrl_generic_to_map reads device tree data and allocates internal pinctrl maps. If any subsequent pinctrl helper routine fails, the code returns an error without freeing previously allocated map entries. This results in a memory leak that propagates to all drivers that use pinctrl_generic_to_map, causing the kernel memory pool to be exhausted over time. The exposed weakness is a classic memory‑allocation error and can lead to a denial‑of‑service condition when the kernel runs out of address space or allocation bandwidth.

Affected Systems

The flaw resides in the Linux kernel. All installations that load the generic pinctrl driver and invoke pinctrl_generic_to_map during boot or driver initialisation are affected. The issue may surface on a wide range of embedded or desktop platforms that use kernel blobs compiled with the generic pinctrl backend.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low probability of exploitation under current conditions, and the vulnerability is not listed in any KEV catalog. Likely exploitation requires the attacker to influence device tree configuration or to trigger repeated failures in pinctrl_generic_to_map, which typically demands elevated or privileged access to the system. As a result, the risk remains moderate for environments that rely on dynamic or user‑controlled DT entries, while the risk is low for static, provider‑controlled configurations. The impact is a bit‑rot style memory depletion that could eventually crash the system, but it is unlikely to allow arbitrary code execution.

Generated by OpenCVE AI on September 19, 2026 at 04:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a revision that contains the commit fixing pinctrl_generic_to_map to free maps on error. The patch is available in kernel commits 09f47abc95ee9e819e7e93cd68c1c23abe11c842 and 17007cd700601777d9ee203a13d97e64ece3a10f; apply these and rebuild the kernel with the affected configuration.
  • If an immediate kernel upgrade is not possible, rebuild the kernel with the new commit applied and reboot the system to ensure the corrected pinctrl code is active.
  • Verify that device tree configurations that could trigger this path are validated or simplified to avoid repeated allocation failures; consider disabling irrelevant pinctrl groups if they are not needed for the target hardware.

Generated by OpenCVE AI on September 19, 2026 at 04:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: pinctrl: generic: free maps on pinctrl_generic_to_map() failure pinctrl_generic_to_map() parses DT configuration and allocates pinctrl maps via pinctrl_utils_reserve_map(). If subsequent steps (such as pinctrl_utils_add_map_mux(), pinctrl_generic_add_group(), pinconf_generic_parse_dt_config(), or pinctrl_utils_add_map_configs()) return an error, *maps may contain partially allocated map entries. Returning the error directly without freeing *maps leaks the allocated mapping memory across all drivers that rely on pinctrl_generic_to_map(). Fix this by calling pinctrl_utils_free_map() and resetting *maps, *num_maps, and *num_reserved_maps in the error path of pinctrl_generic_to_map().
Title pinctrl: generic: free maps on pinctrl_generic_to_map() failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:51.635Z

Reserved: 2026-09-11T19:38:34.804Z

Link: CVE-2026-90340

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:32.633

Modified: 2026-09-17T17:17:32.633

Link: CVE-2026-90340

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T06:45:16Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime