Description
In the Linux kernel, the following vulnerability has been resolved:

remoteproc: qcom_q6v5_adsp: Fix reference leak for device node

When calling of_parse_phandle_with_args(), the caller is responsible
to call of_node_put() to release the reference of device node.
In adsp_map_carveout, it does not release the reference.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion (Denial of Service)
Action: Apply Update
AI Analysis

Impact

The kernel driver for Qualcomm qcom_q6v5_adsp fails to decrement the reference count on a device node after parsing its properties. The resulting reference leak can cause the device node to remain in memory indefinitely, eventually exhausting kernel resources and potentially leading to a denial‑of‑service state. The vulnerability is a classic reference‑counting error that can grow unbounded per invocation of the affected function.

Affected Systems

Any Linux kernel running the remoteproc driver for the Qualcomm qcom_q6v5_adsp module is affected. The issue exists in versions of the kernel prior to the patch that adds a call to of_node_put() in adsp_map_carveout. Because the vendor list is simply "Linux:Linux", the risk applies to all distributions that include the unpatched kernel.

Risk and Exploitability

The EPSS score is reported as less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. However, an attacker with the ability to invoke the affected function repeatedly—such as a privileged user or a malicious kernel module—could expedite resource exhaustion. The attack vector is local to the kernel, requiring code that can trigger the reference leak through the remoteproc interface.

Generated by OpenCVE AI on September 19, 2026 at 07:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install a kernel version that includes the fix for the reference leak in the qcom_q6v5_adsp driver.
  • If an update is not immediately available, disable the remoteproc module or the Qualcomm qcom_q6v5_adsp driver until a patched kernel is released.
  • Monitor kernel logs and resource usage for signs of unattended device‑node reference counts to detect potential exploitation in the interim.

Generated by OpenCVE AI on September 19, 2026 at 07:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_q6v5_adsp: Fix reference leak for device node When calling of_parse_phandle_with_args(), the caller is responsible to call of_node_put() to release the reference of device node. In adsp_map_carveout, it does not release the reference.
Title remoteproc: qcom_q6v5_adsp: Fix reference leak for device node
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:30.565Z

Reserved: 2026-09-17T16:02:15.087Z

Link: CVE-2026-93126

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:07.347

Modified: 2026-09-17T17:18:07.347

Link: CVE-2026-93126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:15:17Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime