---
cve: "CVE-2026-23260"
severity: "LOW"
cvss: 3.1
epss: "11%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-03-18 18:16:24"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-09T12:26:02+02:00"
---

# CVE-2026-23260

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

regmap: maple: free entry on mas_store_gfp() failure

regcache_maple_write() allocates a new block ('entry') to merge
adjacent ranges and then stores it with mas_store_gfp().
When mas_store_gfp() fails, the new 'entry' remains allocated and
is never freed, leaking memory.

Free 'entry' on the failure path; on success continue freeing the
replaced neighbor blocks ('lower', 'upper').

## Patch verfügbar (OSV)

- Kernel ≥ 6.6.124
- Kernel ≥ 6.12.70
- Kernel ≥ 6.18.10

## Referenzen

- <https://git.kernel.org/stable/c/d61171cf097156030142643942c217759a9cc806>
- <https://git.kernel.org/stable/c/811b45e2d795d955bb7fd9c816b40036f4fde350>
- <https://git.kernel.org/stable/c/f08f2d2907675926ac5657b25f86d921f269602a>
- <https://git.kernel.org/stable/c/f3f380ce6b3d5c9805c7e0b3d5bc28d9ec41e2e8>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-23260) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
