SB20260918448 - Missing Release of Resource after Effective Lifetime in Linux kernel hw cxgb4 driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-90219)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a resource leak.
The vulnerability exists due to missing release of debugfs resources in c4iw_dealloc() when RDMA device registration fails. A local user can trigger a failed RDMA device registration to cause a resource leak.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/046425412529dbfca1433c8bef5641b271b4ab2a
- https://git.kernel.org/stable/c/459b59f7ed56511d6529311cb4e5e482ebfcfb8e
- https://git.kernel.org/stable/c/479a7f90060e62bdd9bb4036ec0a70bf460f6d23
- https://git.kernel.org/stable/c/c332d9e7dce234d8bef78271d003a68ee943b61b
- https://git.kernel.org/stable/c/cd60992f09b7e83bfd3c76e3bb06b29f3e2fa0a8
- https://git.kernel.org/stable/c/ea41b5630fa3d9877ce9ed8832cf5575f742bfbb
- https://git.kernel.org/stable/c/f98e894ec029a752cf9c7f7834741bead0fb463d
- https://git.kernel.org/stable/c/fe5c16bb6252dea6025b748257ddc3b2665495b0