CVE-2026-43397

Updated on 08 May 2026

Severity

5.5 Medium severity

Details

CVSS score
5.5

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: samsung-dsim: Fix memory leak in error path In samsung_dsim_host_attach(), drm_bridge_add() is called to add the bridge. However, if samsung_dsim_register_te_irq() or pdata->host_ops->attach() fails afterwards, the function returns without removing the bridge, causing a memory leak. Fix this by adding proper error handling with goto labels to ensure drm_bridge_remove() is called in all error paths. Also ensure that samsung_dsim_unregister_te_irq() is called if the attach operation fails after the TE IRQ has been registered. samsung_dsim_unregister_te_irq() function is moved without changes to be before samsung_dsim_host_attach() to avoid forward declaration. A flaw was found in the Linux kernel’s drm/bridge: samsung-dsim module. Improper error handling in the samsung_dsim_host_attach() function can lead to a memory leak. If the drm_bridge_add() operation is successful but subsequent operations fail, the bridge is not properly removed, causing memory to be retained. Over time, this unreleased memory can accumulate, potentially leading to a Denial of Service (DoS) condition where the system becomes unstable or unresponsive.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 13 Planned
Ubuntu 24.04 Planned