Improper resource shutdown or release in Linux kernel - CVE-2026-64461

 

Improper resource shutdown or release in Linux kernel - CVE-2026-64461

Published: July 27, 2026


Vulnerability identifier: #VU139475
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64461
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in the MediaTek PCIe controller driver when enabling a port fails during setup. A local user can trigger a port initialization failure to cause a denial of service.

The issue occurs in the probe error path after IRQ domains have already been created for the port.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-64461

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.100-1

External References

Related Security Bulletins