Improper resource shutdown or release in Linux kernel - CVE-2026-64461
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the MediaTek PCIe controller driver when enabling a port fails during setup. A local user can trigger a port initialization failure to cause a denial of service.
The issue occurs in the probe error path after IRQ domains have already been created for the port.
Affected software
Debian Linux
Ubuntu
linux (Debian package)
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-64461
linux (Debian package) - update to 6.12.100-1
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/1fbe8972a39548a633d06d7b03a01b7b119a2c12
- https://git.kernel.org/stable/c/6e6a529d6f779413379b4404c9ef6a36c0337225
- https://git.kernel.org/stable/c/ce52e494a7555bdae1d990a2654fd7547ef6d986
- https://git.kernel.org/stable/c/df77314b3bedbd9ad5d6f0682f98b99e3c5f7e2e
- https://git.kernel.org/stable/c/e23da72ef202654a7d5269885c4fa39a8404db76
- https://git.kernel.org/stable/c/ec7c05eed47d8b15c45380aee7ca168a82e15035
- https://git.kernel.org/stable/c/f865a57896bd92d7662eb2818d8f48872e2cbbc7
- https://git.kernel.org/stable/c/fe8c701a53c2816cd82301f66c671d952003c1b0