Improper resource shutdown or release in Linux kernel - CVE-2026-63862
Published: July 20, 2026
Vulnerability identifier: #VU138784
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-63862
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in mtk_pcie_setup_irq() when fetching the controller IRQ after allocating IRQ domains. A local user can trigger initialization failure conditions to cause a denial of service.
How to mitigate CVE-2026-63862
Install security update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/07a5ecb94768cbf76fe659e9924000e9ced0c8a6
- https://git.kernel.org/stable/c/0a2d60edc3e57c9512e239ebdfd12204d3368560
- https://git.kernel.org/stable/c/215d4273347b9010a9deae378b0df79c163f707d
- https://git.kernel.org/stable/c/5573c44cb3fd01a9f62d569ae9ac870ef5f0e0ba
- https://git.kernel.org/stable/c/946b31b5a699a2760ee52af0055e5ebf29c5f4cb
- https://git.kernel.org/stable/c/abd3c1927d33766aef39c4640880e3d2637429c2