Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-90352
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a resource leak.
The vulnerability exists due to failure to release a resource in the mt7915 PCI probe routine when IRQ vector allocation or primary IRQ request setup fails. A local privileged user can initiate probing of an mt7915 PCI device under an IRQ setup failure condition to cause a resource leak.
Affected software
How to mitigate CVE-2026-90352
External References
- https://git.kernel.org/stable/c/2a434d2637b9c9be9bcc8a84dc46880cc1446643
- https://git.kernel.org/stable/c/5c30a6350a300fbb800831f1b4373b2f59e03410
- https://git.kernel.org/stable/c/8370aebd26a9dfa2e0de665e3ab504c0e97ee730
- https://git.kernel.org/stable/c/8a2e38019846da29a112fac4dd96fe5bfa298faf
- https://git.kernel.org/stable/c/ed5cc46a3c8f4fe7f549c661914d8d835169acc0
- https://git.kernel.org/stable/c/fb9c7b4c238b4e5469a11a1fb8cf332f6193b995