Description
In the Linux kernel, the following vulnerability has been resolved:

irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure

imsic_early_acpi_init() allocates a firmware node before setting up the
IMSIC state. If imsic_setup_state() fails, the function returns without
freeing the allocated fwnode.

Free the fwnode and clear the global pointer on this error path, matching
the cleanup already done when imsic_early_probe() fails.

[ tglx: Use a common cleanup path instead of copying code around ]
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the Linux kernel, the IMSIC early ACPI initialization routine can allocate a firmware node and then, if the IMSIC state setup fails, fail to free that node. The result is a memory leak that persists until the driver is reloaded or the system is rebooted. The leaked reference consumes kernel memory over time, potentially degrading system performance or leading to a denial‑of‑service state for processes that require kernel resources.

Affected Systems

The vulnerability affects all Linux kernel builds that include the IMSIC early ACPI driver for RISC‑V, as identified by the Linux kernel CPE namespace. No specific kernel version range is supplied in the advisory, so any build that compiles this code and enables the driver may be impacted until the patch is applied.

Risk and Exploitability

The CVSS score of 5.5 and an EPSS score of less than 1% indicate a moderate severity but a very low documented exploitation probability. The defect is internal to the kernel; it is not publicly known to be exploitable from user space. Based on the description, it is inferred that the error path is triggered during early boot or when the driver is probed, which requires kernel execution context. An attacker would therefore need to cause the IMSIC state setup to fail—e.g., by supplying malformed or missing ACPI data—to trigger the leak. The risk of exploitation is further mitigated by the lack of a publicly available exploit and the fact that the vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 18, 2026 at 03:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the patched imsic_early_acpi_init function, which frees the firmware node on error.
  • Reboot the system to reload the driver and clear any leaked firmware nodes.
  • If early IMSIC ACPI support is not required, disable the IMSIC early ACPI driver via kernel configuration to prevent the leak from occurring.
  • Monitor dmesg or other kernel logs for 'imsic_early' error messages to detect repeated failures and validate that the leak is no longer occurring.

Generated by OpenCVE AI on August 18, 2026 at 03:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure imsic_early_acpi_init() allocates a firmware node before setting up the IMSIC state. If imsic_setup_state() fails, the function returns without freeing the allocated fwnode. Free the fwnode and clear the global pointer on this error path, matching the cleanup already done when imsic_early_probe() fails. [ tglx: Use a common cleanup path instead of copying code around ]
Title irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:06:49.893Z

Reserved: 2026-08-09T03:40:39.900Z

Link: CVE-2026-72026

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:01.730

Modified: 2026-08-17T06:18:00.330

Link: CVE-2026-72026

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72026 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T04:00:10Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime