SB20260816124 - Improper resource shutdown or release in Linux kernel mediatek mt8192
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-72259)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the MT8192 AFE probe path when handling reserved memory assignment during device probe and driver cleanup. A local user can trigger device probe failure or driver unbind to cause a denial of service.
The issue occurs when reserved memory is successfully assigned and is not released during cleanup.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4c9df23e121f1095f02cc7e1531ce3a6d74ff697
- https://git.kernel.org/stable/c/51c367230e30ed80b49d5330831c1f2c59405b02
- https://git.kernel.org/stable/c/756cfc0039fe9dc1388ea231821508a78a087afe
- https://git.kernel.org/stable/c/965e17ae6751c5d3302430c8ebd650e72d45a85f
- https://git.kernel.org/stable/c/989cbe8cc86f4639f4e1fbe84ea0339759e92f1f