๐Ÿ” CVE Alert

CVE-2026-64376

UNKNOWN 0.0

firmware_loader: fix device reference leak in firmware_upload_register()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: firmware_loader: fix device reference leak in firmware_upload_register() firmware_upload_register() -> fw_create_instance() -> device_initialize() After fw_create_instance() succeeds, the lifetime of the embedded struct device is expected to be managed through the device core reference counting, since fw_create_instance() has already called device_initialize(). In firmware_upload_register(), if alloc_lookup_fw_priv() fails after fw_create_instance() succeeds, the code reaches free_fw_sysfs and frees fw_sysfs directly instead of releasing the device reference with put_device(). This may leave the reference count of the embedded struct device unbalanced, resulting in a refcount leak. The issue was identified by a static analysis tool I developed and confirmed by manual review. Fix this by using put_device(fw_dev) in the failure path and letting fw_dev_release() handle the final cleanup, instead of freeing the instance directly from the error path.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
97730bbb242cde22b7140acd202ffd88823886c9 < 517676ec7dfca064e08f94007a4abd21969de0a0 97730bbb242cde22b7140acd202ffd88823886c9 < 46d403da376a8b7c1187193294953816e1a8d7fe 97730bbb242cde22b7140acd202ffd88823886c9 < 2619b47a0c8114eef980a56ade7e3ef4b58eb384 97730bbb242cde22b7140acd202ffd88823886c9 < 92f41769e5fd16bcd9ba97500d0517332e0a5b45 97730bbb242cde22b7140acd202ffd88823886c9 < 15432f19562fdb9199cce6d9fc24db12c71ed574 97730bbb242cde22b7140acd202ffd88823886c9 < 896df22ee57648b0c505bd76ddbc6b2341834696
Linux / Linux
5.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/517676ec7dfca064e08f94007a4abd21969de0a0 git.kernel.org: https://git.kernel.org/stable/c/46d403da376a8b7c1187193294953816e1a8d7fe git.kernel.org: https://git.kernel.org/stable/c/2619b47a0c8114eef980a56ade7e3ef4b58eb384 git.kernel.org: https://git.kernel.org/stable/c/92f41769e5fd16bcd9ba97500d0517332e0a5b45 git.kernel.org: https://git.kernel.org/stable/c/15432f19562fdb9199cce6d9fc24db12c71ed574 git.kernel.org: https://git.kernel.org/stable/c/896df22ee57648b0c505bd76ddbc6b2341834696