Improper resource shutdown or release in Linux kernel - CVE-2026-45900
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in dpaa2_caam_probe and dpaa2_dpseci_free when handling probe error paths after dpaa2_dpseci_dpio_setup() failure. A local user can trigger repeated probe failures to cause a denial of service.
The issue occurs when DPIO devices are not ready yet and deferred probing retries the operation, leaving previously allocated netdev-related objects unfreed.