SB20260812367 - Improper resource shutdown or release in Linux kernel hwtracing intel_th driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-68180)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the intel_th MSC output release path when opening and closing MSC output files. A local user can repeatedly open MSC output files to cause a denial of service.
Each successful MSC output open leaks one device reference because the release callback used for MSC outputs does not drop the reference acquired during open.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/26e27b8dcef1e4df6f30d8f25b3304a506d482b3
- https://git.kernel.org/stable/c/761b785a0cfbce43761227bc42a7f984f31f8921
- https://git.kernel.org/stable/c/c3a28f9cb82425fe0835048ed3677f321e780691
- https://git.kernel.org/stable/c/caba30eb8bd321c465ecfc7d850ee85f5b353496
- https://git.kernel.org/stable/c/ddcf2064d7ec5a8c9afa7cb74442320e443502bc