SB20260727269 - Missing Release of Resource after Effective Lifetime in Linux kernel regulator driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-64301)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a reference count leak in scmi_regulator_probe() in the SCMI regulator driver when processing device tree child nodes. A local user can trigger an error condition during device probing to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1e446e8f8c763be3de7d0362e024cdf46194ffef
- https://git.kernel.org/stable/c/22cb337370e6539b0418832c6040e9b00c1b74ca
- https://git.kernel.org/stable/c/3e1441a4d06d35a314961e40057bd1f0106bbc14
- https://git.kernel.org/stable/c/637c11e3d8d43a7ee654591cda8d17c55a9234fa
- https://git.kernel.org/stable/c/a935b64548fcfe1d5b4dbdd31dddfb0d7019367f
- https://git.kernel.org/stable/c/e2baf8ea13fb4b10bec2c4751aea05c00dabcd0f
- https://git.kernel.org/stable/c/fa11039d6cdff84584a3ef8cc1f5e1b56e045da2