Linux Kernel GPIO Aggregator Software Node Leak Vulnerability

Vulnerability

A vulnerability in the Linux kernel's GPIO aggregator component has been addressed. When the aggregator platform device, managed through configfs, is deactivated, the dynamically created software node is not properly removed, leading to a memory leak. The vulnerability has been fixed by ensuring the software node is destroyed as the final step in the deactivation process.

Impact

The vulnerability could lead to a memory leak by failing to properly remove the software node associated with the GPIO aggregator when the device is deactivated.

Added: Jul 19, 2026, 6:35 PM
Updated: Jul 19, 2026, 6:35 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
3.1
remediation
7.7
relevance
9.7
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.