Improper resource shutdown or release in Linux kernel - CVE-2026-80565
Published: August 27, 2026
Vulnerability identifier: #VU145926
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80565
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to improper resource shutdown or release in the qce algorithm registration logic in drivers/crypto/qce/core.c when handling a failure during algorithm registration. A local user can trigger a registration failure to execute arbitrary code.
Affected software
Linux kernel
How to mitigate CVE-2026-80565
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/1ece8e16c085e8cd60ecbdb641269aaa53d31da4
- https://git.kernel.org/stable/c/4e88b4fda48282f3fd504b4d4f5d2d4f996b76ce
- https://git.kernel.org/stable/c/9c75402286409f5e1a75e4a445555c84066f89db
- https://git.kernel.org/stable/c/a134e4b8102c077286818ee112b9f925db613d4c
- https://git.kernel.org/stable/c/c7dc487aade12c692add3221673c9bdf32dc24f5
- https://git.kernel.org/stable/c/dbca8b798caf47fb2799a26dd09c9ad66305883d
- https://git.kernel.org/stable/c/de52c713d21806b93b00a6074056b57aec4f8919
- https://git.kernel.org/stable/c/fef187c6194d67395182d58169dd14ba631f1b41