Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-45883
Published: May 28, 2026
Vulnerability identifier: #VU132601
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-45883
CWE-ID: CWE-772
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a resource leak in sca3000_probe() when handling device initialization failures. A local user can trigger initialization that causes iio_device_register() to fail to cause a denial of service.
How to mitigate CVE-2026-45883
Install security update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/103ac8e3a7f345a0966ef582b8a874ac31a92c7c
- https://git.kernel.org/stable/c/40c860ece22542178cddcf01b08644bcdbc597b3
- https://git.kernel.org/stable/c/517d9f2b963089b3d64c23accf7920d77f5a30c8
- https://git.kernel.org/stable/c/55e13abf22c27a3b0ab5cf941dd07a2d9786736c
- https://git.kernel.org/stable/c/597d749c5180f3e351837e851a6131b140324e9f
- https://git.kernel.org/stable/c/62b44ebc1f2c71db3ca2d4737c52e433f6f03038
- https://git.kernel.org/stable/c/84d3c396d8ae73c24dececfcc4e544ea09311e32
- https://git.kernel.org/stable/c/e8e960c3d23fdb4882d70d34ce762368da0f1427