
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23170 is a memory leak vulnerability in the Linux kernel's DRM (Direct Rendering Manager) imx/tve driver, classified under CWE-401 (Missing Release of Memory after Effective Lifetime). The driver fails to drop the reference taken to the DDC (Display Data Channel) device during probe failure (e.g., probe deferral) and on driver unbind, resulting in unreleased device references. It affects Linux kernel versions from 3.10 through multiple stable branches up to 6.18.8, as well as 6.19-rc1 through rc7. The vulnerability was published on February 14, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly).
The root cause is improper resource management (CWE-401) in the drm/imx/tve driver's probe function, which acquires a reference to the DDC device but does not release it upon probe failure or driver unbind. This is a local vulnerability requiring low privileges and no user interaction; an attacker must be able to trigger probe failures or driver unbind operations on a system with affected i.MX TVE display hardware. The fix, applied across multiple stable kernel branches, ensures the DDC device reference is properly dropped in both error and cleanup paths (Feedly, Kernel Patch).
Successful exploitation can lead to a denial of service through resource exhaustion, as unreleased DDC device references accumulate over repeated probe/unbind cycles, eventually causing kernel memory pressure or preventing proper operation of the display subsystem. The vulnerability has no confidentiality or integrity impact; only availability is affected. Systems using i.MX TVE display hardware are at risk, and the impact is limited to the local system with no known lateral movement potential (Feedly).
Apply the available kernel patches from the stable branch matching your kernel version. Fixed versions include 5.10.249, 5.15.199, 6.1.162, 6.6.123, 6.12.69, and 6.18.9, with corresponding updates to 6.19-rc releases. Patches are available via the Linux kernel stable tree (Kernel Patch). Ubuntu users should apply the relevant USN advisories (e.g., USN-8162-1, USN-8180-1 through USN-8180-6, USN-8186-1, USN-8188-1, USN-8275-1, USN-8297-1) as distributed by Canonical (Ubuntu USN-8162-1, Ubuntu USN-8180-1). No configuration-based workaround is available; upgrading to a patched kernel version is the only remediation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."