Linux Kernel Remoteproc Memory Leak Vulnerability in qcom_q6v5_mss

Vulnerability

A vulnerability in the Linux kernel's remoteproc subsystem, specifically within the qcom_q6v5_mss component, has been addressed. The issue involved memory leaks related to device_node pointers, which are returned with an incremented reference count. The vulnerability arose because the code failed to properly release these pointers in certain error cases, leading to resource leaks.

Impact

The vulnerability could lead to memory leaks, causing increased memory usage and potentially degrading system performance over time.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.