Database/Control plane, storage & DevOps
Linux amd-pstate - memory leak in amd_pstate_epp_cpu_init(): On failure to set the energy-performance preference
CVSS 5.5CVE-2026-53121Control plane, storage & DevOpscurated
Impact
On failure to set the energy-performance preference, amd_pstate_epp_cpu_init() returns without freeing what it allocated. Another slow leak in the AMD CPU frequency driver, hit on the error path - which is the path a misconfigured or partially-supported platform takes repeatedly rather than once.
Who can reach it
Local, on the amd-pstate initialisation error path.
What to do
Distro kernel update plus reboot. Batch with the other amd-pstate fixes.
References
Related entries
- Linux iommu/amd - devid bounds check in __rlookup_amd_iommu(): The AMD IOMMU driver looked up device IDs withoutCVE-2026-53283 · Linux iommu/amd - devid bounds check in __rlookup_amd_iommu()Medium
- Linuxfabrik monitoring plugins: sudo-authorized checks read arbitrary root-readable files via --testCVE-2026-73974 · Linuxfabrik Monitoring Plugins / linuxfabrik-lib (lib.lftest.test --test path handling)Medium
- community.general ipa_getkeytab: IPA/LDAP bind password written to logs and exposed in the process listCVE-2026-80158 · Ansible community.general ipa_getkeytab module (bind_pw not declared no_log)Medium
- Harbor (audit log redaction, LDAP password and OIDC client secret): CREDENTIAL DISCLOSURE VIA THE AUDIT TRAIL: HarborNCVD-2026-058-harbor-audit-log-redaction-ldap · Harbor (audit log redaction, LDAP password and OIDC client secret)Medium
- Kubeflow (central dashboard, reflected cross-site scripting): Reflected XSS in the Kubeflow dashboard runs attackerCVE-2023-6571 · Kubeflow (central dashboard, reflected cross-site scripting)Medium
- GitLab CE/EE: missing enforcement checks let an authenticated user bypass SAML SSO restrictionsCVE-2026-12910 · GitLab CE/EE (SAML SSO sign-in enforcement)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.