Improper resource shutdown or release in Linux kernel - CVE-2026-100079

 

Improper resource shutdown or release in Linux kernel - CVE-2026-100079

Published: September 28, 2026


Vulnerability identifier: #VU152271
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-100079
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to prevent UCSI debugfs entries from being created.

The vulnerability exists due to improper resource cleanup in UCSI debugfs entry teardown when unregistering and registering the same UCSI instance across a remoteproc restart. A local user can trigger repeated UCSI instance unregistration and registration to prevent UCSI debugfs entries from being created.


Affected software

Linux kernel

How to mitigate CVE-2026-100079

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins