Improper resource shutdown or release in Linux kernel - CVE-2026-90273
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause active configuration reference leaks.
The vulnerability exists due to improper resource shutdown or release in the ETMv4 CoreSight perf enable path when branch broadcast is selected but unsupported by the hardware or hardware enablement fails. A local user can enable a perf event that encounters either error condition to cause active configuration reference leaks.