CVE-2026-23123 PUBLISHED

interconnect: debugfs: initialize src_node and dst_node to empty strings

Assigner: Linux
Reserved: 13.01.2026 Published: 14.02.2026 Updated: 14.02.2026

In the Linux kernel, the following vulnerability has been resolved:

interconnect: debugfs: initialize src_node and dst_node to empty strings

The debugfs_create_str() API assumes that the string pointer is either NULL or points to valid kmalloc() memory. Leaving the pointer uninitialized can cause problems.

Initialize src_node and dst_node to empty strings before creating the debugfs entries to guarantee that reads and writes are safe.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 770c69f037c18cfaa37c3d6c6ef8bd257635513f to aa79a5a959c7c414bd6fba01ea8dbaddd44f13e7 (excl.)
  • affected from 770c69f037c18cfaa37c3d6c6ef8bd257635513f to 935d0938b570589c8b0a1733d2cba3c39d027f25 (excl.)
  • affected from 770c69f037c18cfaa37c3d6c6ef8bd257635513f to 5d7c7e1fb3ec24fdd0f9faa27b666d6789e891e8 (excl.)
  • affected from 770c69f037c18cfaa37c3d6c6ef8bd257635513f to 8cc27f5c6dd17dd090f3a696683f04336c162ff5 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.6 is affected
  • unaffected from 0 to 6.6 (excl.)
  • unaffected from 6.6.122 to 6.6.* (incl.)
  • unaffected from 6.12.68 to 6.12.* (incl.)
  • unaffected from 6.18.8 to 6.18.* (incl.)
  • unaffected from 6.19 to * (incl.)

References