SB20260918312 - Missing Release of Resource after Effective Lifetime in Linux kernel mt76 mt7915 driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-90352)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause a resource leak.
The vulnerability exists due to failure to release a resource in the mt7915 PCI probe routine when IRQ vector allocation or primary IRQ request setup fails. A local privileged user can initiate probing of an mt7915 PCI device under an IRQ setup failure condition to cause a resource leak.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2a434d2637b9c9be9bcc8a84dc46880cc1446643
- https://git.kernel.org/stable/c/5c30a6350a300fbb800831f1b4373b2f59e03410
- https://git.kernel.org/stable/c/8370aebd26a9dfa2e0de665e3ab504c0e97ee730
- https://git.kernel.org/stable/c/8a2e38019846da29a112fac4dd96fe5bfa298faf
- https://git.kernel.org/stable/c/ed5cc46a3c8f4fe7f549c661914d8d835169acc0
- https://git.kernel.org/stable/c/fb9c7b4c238b4e5469a11a1fb8cf332f6193b995