SB2026082772 - Improper resource shutdown or release in Linux kernel crypto qce driver
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-80565)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to improper resource shutdown or release in the qce algorithm registration logic in drivers/crypto/qce/core.c when handling a failure during algorithm registration. A local user can trigger a registration failure to execute arbitrary code.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1ece8e16c085e8cd60ecbdb641269aaa53d31da4
- https://git.kernel.org/stable/c/4e88b4fda48282f3fd504b4d4f5d2d4f996b76ce
- https://git.kernel.org/stable/c/9c75402286409f5e1a75e4a445555c84066f89db
- https://git.kernel.org/stable/c/a134e4b8102c077286818ee112b9f925db613d4c
- https://git.kernel.org/stable/c/c7dc487aade12c692add3221673c9bdf32dc24f5
- https://git.kernel.org/stable/c/dbca8b798caf47fb2799a26dd09c9ad66305883d
- https://git.kernel.org/stable/c/de52c713d21806b93b00a6074056b57aec4f8919
- https://git.kernel.org/stable/c/fef187c6194d67395182d58169dd14ba631f1b41