drm/bridge: samsung-dsim: Fix memory leak in error path
Published May 8, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.16%
Description
In samsung_dsim_host_attach(), drm_bridge_add() is called to add the bridge. However, if samsung_dsim_register_te_irq() or pdata->host_ops->attach() fails afterwards, the function returns without removing the bridge, causing a memory leak.
Fix this by adding proper error handling with goto labels to ensure drm_bridge_remove() is called in all error paths. Also ensure that samsung_dsim_unregister_te_irq() is called if the attach operation fails after the TE IRQ has been registered.
samsung_dsim_unregister_te_irq() function is moved without changes to be before samsung_dsim_host_attach() to avoid forward declaration.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.4StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.4
- Version 6.12.78StatusunaffectedConstraints<=6.12.*
- Version 6.18.19StatusunaffectedConstraints<=6.18.*
- Version 6.19.9StatusunaffectedConstraints<=6.19.*
- Version 6.6.130StatusunaffectedConstraints<=6.6.*
- Version 7.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 6.4 · < 6.6.130
- ≥ 6.7 · < 6.12.78
- ≥ 6.13 · < 6.18.19
- ≥ 6.19 · < 6.19.9
- 7.0
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-43397 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468188 Issue Tracking
- https://git.kernel.org/stable/c/0b07f7d2c5a4078c2f1c11bb36685084fe4e5c95 Patch
- https://git.kernel.org/stable/c/803ec1faf7c1823e6e3b1f2aaa81be18528c9436 Patch
- https://git.kernel.org/stable/c/98310fe3a2a79671b739a5344c1a11d74c503e25 Patch
- https://git.kernel.org/stable/c/a40b92fb4b26d4cb1b5e439e55a56db7e79a82d1 Patch
- https://git.kernel.org/stable/c/e6d779654cda63d632bd8dfcdcabd125057e30a5 Patch
- https://lore.kernel.org/linux-cve-announce/2026050838-CVE-2026-43397-2864@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-43397
- https://www.cve.org/CVERecord?id=CVE-2026-43397
Change history (0)
No recorded changes yet.