Improper resource shutdown or release in Linux kernel - CVE-2026-64461
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the MediaTek PCIe controller driver when enabling a port fails during setup. A local user can trigger a port initialization failure to cause a denial of service.
The issue occurs in the probe error path after IRQ domains have already been created for the port.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64461
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/1fbe8972a39548a633d06d7b03a01b7b119a2c12
- https://git.kernel.org/stable/c/6e6a529d6f779413379b4404c9ef6a36c0337225
- https://git.kernel.org/stable/c/ce52e494a7555bdae1d990a2654fd7547ef6d986
- https://git.kernel.org/stable/c/df77314b3bedbd9ad5d6f0682f98b99e3c5f7e2e
- https://git.kernel.org/stable/c/e23da72ef202654a7d5269885c4fa39a8404db76
- https://git.kernel.org/stable/c/ec7c05eed47d8b15c45380aee7ca168a82e15035
- https://git.kernel.org/stable/c/f865a57896bd92d7662eb2818d8f48872e2cbbc7
- https://git.kernel.org/stable/c/fe8c701a53c2816cd82301f66c671d952003c1b0