Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-90354
Published: September 18, 2026
Vulnerability identifier: #VU151126
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90354
CWE-ID: CWE-772
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a device reference leak.
The vulnerability exists due to improper resource management in the mt7915_pci_probe HIF2 initialization path when initializing HIF2 on non-WED dual-HIF hardware. A local user can trigger initialization of the mt7915 PCI device to cause a device reference leak.
Affected software
Linux kernel
How to mitigate CVE-2026-90354
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/249cbaa1873550689fab136b74982cbba74c4169
- https://git.kernel.org/stable/c/29fbc5256c2d8448f084ff179d2e5092ecd1fc54
- https://git.kernel.org/stable/c/3ae8ad277e2819a281b0e36b55633c8515c16ce7
- https://git.kernel.org/stable/c/927fe8c0eb8c10295bc0018c8faa4d91f8fe98c6
- https://git.kernel.org/stable/c/bd2e8f535ae35beb45a7fcc17ec9bbf8dc4db5fe
- https://git.kernel.org/stable/c/eac18fadc791928379b179e54636494b92f8cf86