Improper resource shutdown or release in Linux kernel - CVE-2026-90273

 

Improper resource shutdown or release in Linux kernel - CVE-2026-90273

Published: September 18, 2026


Vulnerability identifier: #VU151217
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90273
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause active configuration reference leaks.

The vulnerability exists due to improper resource shutdown or release in the ETMv4 CoreSight perf enable path when branch broadcast is selected but unsupported by the hardware or hardware enablement fails. A local user can enable a perf event that encounters either error condition to cause active configuration reference leaks.


Affected software

Linux kernel

How to mitigate CVE-2026-90273

Install security update from vendor's repository.


External References

Related Security Bulletins