SB20260815192 - Improper resource shutdown or release in Linux kernel cavium cpt driver
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-74279)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in the sg_cleanup error path in setup_sgio_components() when cleaning up DMA mappings after a mapping failure. A local user can trigger the error path to cause a denial of service.
The issue leaks successfully mapped DMA entries while repeatedly unmapping the failed entry.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/23c6174e48f66fc10b998b0acdb406cb0caf5c80
- https://git.kernel.org/stable/c/23d3a7e896a1fe2d7a6bcb42f093948b79f8a198
- https://git.kernel.org/stable/c/28141f95ae93b18f9bfde953cb787fcb151fb9da
- https://git.kernel.org/stable/c/3b8a1e1f4e4071a62b20374028744e8cc8310d48
- https://git.kernel.org/stable/c/8afd1007ef79898a6e010eaade97097e49405fce
- https://git.kernel.org/stable/c/9dbf173bd32d5f81b005008b682bfb50aa093455
- https://git.kernel.org/stable/c/d319b83b97b3585550d9ae592dfa78c755b6129e
- https://git.kernel.org/stable/c/fb4d57b83356d4bd411b45ede3024e0ff42c9b5e