SB20260918404 - Improper resource shutdown or release in Linux kernel hwtracing coresight driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-90273)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause active configuration reference leaks.
The vulnerability exists due to improper resource shutdown or release in the ETMv4 CoreSight perf enable path when branch broadcast is selected but unsupported by the hardware or hardware enablement fails. A local user can enable a perf event that encounters either error condition to cause active configuration reference leaks.
Remediation
Install update from vendor's website.