SB20260812102 - Improper resource shutdown or release in Linux kernel intel ipw2x00 driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-68413)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in ipw2100_pci_init_one() when handling error paths during device initialization. A local attacker can trigger initialization failures to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0d388f62031dbabcba0f44bb91b59f10e88cac17
- https://git.kernel.org/stable/c/7cbda50eebcd9aa00b0de382f776287cf7a36cf8
- https://git.kernel.org/stable/c/836a19c654dcb1b01878a70090af016fbd0fd7e5
- https://git.kernel.org/stable/c/f442e581a88937671a22ceb3806c186265ef6254
- https://git.kernel.org/stable/c/f75b9a2a9d8334ae0f9c5e47df7b31f7aeb1fdbe