SB20260812326 - Improper resource shutdown or release in Linux kernel pci dm1105 driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-68218)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the dm1105 driver remove() callback when removing the device. A local user can trigger device removal to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/08ddfd628a2dbd9d385da677afccd893d0ab37e1
- https://git.kernel.org/stable/c/0c2b4c45fce012e88904b8c66b5cd786535c0b8c
- https://git.kernel.org/stable/c/1a65db225b25bb8c8febf16974c060e0cc242eb9
- https://git.kernel.org/stable/c/46715fecc38a2d341c3ff680f295de6e8aec72c0
- https://git.kernel.org/stable/c/8d753c8c37afc0910ed5ddc014645b05d6266add