Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: int1092: Fix potential memory leak in sar_probe()

The memory allocated for device_mode_info in parse_package() called by
sar_get_data() is not freed in some of the error paths in sar_probe().
Fix that by converting to use device managed allocations.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak
Action: Apply Patch
AI Analysis

Impact

This vulnerability is a memory leak in the Linux kernel's platform/x86 int1092 module. The sar_probe() function fails to free the device_mode_info structure allocated in parse_package() when certain error conditions occur. The leak can grow unboundedly, consuming system memory and potentially leading to degraded performance or crashes. It is an example of CWE-772: Improper Release of Resources. No immediate code execution or privilege escalation is possible, but availability is impacted.

Affected Systems

All Linux kernel builds that include the platform/x86 int1092 module are affected. This encompasses mainstream distributions running x86 architectures on servers, desktops, and embedded devices. Any system running a kernel that contains this module is susceptible, regardless of its operational role.

Risk and Exploitability

The CVSS score of 4.4 rates the issue as moderate, focused on availability. The EPSS score of <1% indicates low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation would require a local or privileged user to repeatedly invoke the sar_probe path—possibly via the int1092 device interface—to exhaust memory. The default attack vector is thus local; remote exploitation is unlikely because the module operates in kernel space and no external input is processed.

Generated by OpenCVE AI on September 21, 2026 at 01:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Replace the kernel with a version that incorporates the sar_probe memory‑leak patch.
  • If immediate update cannot be performed, restrict or disable access to the int1092 device interface to prevent accidental error paths.
  • Continuously monitor system memory utilization and kernel logs for repeated sar_probe failures, and schedule a system reboot if memory consumption appears to be escalating.

Generated by OpenCVE AI on September 21, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86: int1092: Fix potential memory leak in sar_probe() The memory allocated for device_mode_info in parse_package() called by sar_get_data() is not freed in some of the error paths in sar_probe(). Fix that by converting to use device managed allocations.
Title platform/x86: int1092: Fix potential memory leak in sar_probe()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:25.748Z

Reserved: 2026-09-11T19:38:34.703Z

Link: CVE-2026-89437

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:23.967

Modified: 2026-10-03T11:17:41.843

Link: CVE-2026-89437

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:07Z

Links: CVE-2026-89437 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:45:07Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime