CVE-2026-64376
In the Linux kernel, the following vulnerability has been resolved:
firmware_loader: fix device reference leak in firmware_upload_register()
After fw_create_instance() succeeds, the lifetime of the embedded struct device is expected to be managed through the device core reference counting, since fw_create_instance() has already called device_initialize().
In firmware_upload_register(), if alloc_lookup_fw_priv() fails after fw_create_instance() succeeds, the code reaches free_fw_sysfs and frees fw_sysfs directly instead of releasing the device reference with put_device(). This may leave the reference count of the embedded struct device unbalanced, resulting in a refcount leak.
Leer descripción completaMostrar menos
The issue was identified by a static analysis tool I developed and confirmed by manual review. Fix this by using put_device(fw_dev) in the failure path and letting fw_dev_release() handle the final cleanup, instead of freeing the instance directly from the error path.
Detalles técnicos trazas, registros y código del informe original
firmware_upload_register()
-> fw_create_instance()
-> device_initialize()CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.12%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- https://git.kernel.org/stable/c/15432f19562fdb9199cce6d9fc24db12c71ed574
- https://git.kernel.org/stable/c/2619b47a0c8114eef980a56ade7e3ef4b58eb384
- https://git.kernel.org/stable/c/46d403da376a8b7c1187193294953816e1a8d7fe
- https://git.kernel.org/stable/c/517676ec7dfca064e08f94007a4abd21969de0a0
- https://git.kernel.org/stable/c/896df22ee57648b0c505bd76ddbc6b2341834696
- https://git.kernel.org/stable/c/92f41769e5fd16bcd9ba97500d0517332e0a5b45
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64376",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "97730bbb242cde22b7140acd202ffd88823886c9",
"lessThan": "517676ec7dfca064e08f94007a4abd21969de0a0",
"versionType": "git"
},
{
"status": "affected",
"version": "97730bbb242cde22b7140acd202ffd88823886c9",
"lessThan": "46d403da376a8b7c1187193294953816e1a8d7fe",
"versionType": "git"
},
{
"status": "affected",
"version": "97730bbb242cde22b7140acd202ffd88823886c9",
"lessThan": "2619b47a0c8114eef980a56ade7e3ef4b58eb384",
"versionType": "git"
},
{
"status": "affected",
"version": "97730bbb242cde22b7140acd202ffd88823886c9",
"lessThan": "92f41769e5fd16bcd9ba97500d0517332e0a5b45",
"versionType": "git"
},
{
"status": "affected",
"version": "97730bbb242cde22b7140acd202ffd88823886c9",
"lessThan": "15432f19562fdb9199cce6d9fc24db12c71ed574",
"versionType": "git"
},
{
"status": "affected",
"version": "97730bbb242cde22b7140acd202ffd88823886c9",
"lessThan": "896df22ee57648b0c505bd76ddbc6b2341834696",
"versionType": "git"
}
],
"programFiles": [
"drivers/base/firmware_loader/sysfs_upload.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/base/firmware_loader/sysfs_upload.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-25T10:17:20.717",
"references": [
{
"url": "https://git.kernel.org/stable/c/15432f19562fdb9199cce6d9fc24db12c71ed574",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2619b47a0c8114eef980a56ade7e3ef4b58eb384",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/46d403da376a8b7c1187193294953816e1a8d7fe",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/517676ec7dfca064e08f94007a4abd21969de0a0",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/896df22ee57648b0c505bd76ddbc6b2341834696",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/92f41769e5fd16bcd9ba97500d0517332e0a5b45",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware_loader: fix device reference leak in firmware_upload_register()\n\nfirmware_upload_register()\n -> fw_create_instance()\n -> device_initialize()\n\nAfter fw_create_instance() succeeds, the lifetime of the embedded struct\ndevice is expected to be managed through the device core reference\ncounting, since fw_create_instance() has already called\ndevice_initialize().\n\nIn firmware_upload_register(), if alloc_lookup_fw_priv() fails after\nfw_create_instance() succeeds, the code reaches free_fw_sysfs and frees\nfw_sysfs directly instead of releasing the device reference with\nput_device(). This may leave the reference count of the embedded struct\ndevice unbalanced, resulting in a refcount leak.\n\nThe issue was identified by a static analysis tool I developed and\nconfirmed by manual review. Fix this by using put_device(fw_dev) in the\nfailure path and letting fw_dev_release() handle the final cleanup,\ninstead of freeing the instance directly from the error path."
}
],
"lastModified": "2026-09-08T14:21:55.037",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CFE34378-E34A-4EB8-94FC-23E73A95EB5D",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7046B092-F810-4440-ACE6-60218518EECE",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38A8100E-2B1A-462F-AEE9-8901B870FEF2",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "914AE4BC-3D59-4C5A-9DB5-9CE327B429F7",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6228DDD6-4557-4AA3-9F43-AB995D471E42",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.19"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}