Description
In the Linux kernel, the following vulnerability has been resolved:

firewire: core: fix memory leak in error path of build_tree()

In the error path of build_tree(), node instances can remain in the local
linked list when the function returns.

Whenever an invalid value is detected in the self ID sequence, each
allocated node instance is either an entry in the linked list or an
entry in the ports array of its parent node. Therefore, the allocate
node instances can be safely released by traversing the linked list from
its head.

Release the remaining node instances with for_each_fw_node() before
returning to the caller.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak
Action: Apply Patch
AI Analysis

Impact

The flaw in the FireWire subsystem causes a memory leak when build_tree() encounters an invalid identifier sequence. Node objects that are created as part of parsing the tree are not removed from the linked list on error, resulting in unreferenced kernel memory remaining allocated until the system eventually runs out of memory or the kernel is reloaded.

Affected Systems

This issue affects the Linux kernel’s FireWire core driver. All kernel versions that include the build_tree() function in the firewire module are subject to the leak; specific release numbers are not listed in the advisory, so any installed kernel that has not yet received the patch is vulnerable.

Risk and Exploitability

The EPSS score indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The absence of a CVSS score suggests that the impact is primarily denial‑of‑service through resource exhaustion rather than direct privilege escalation. Attacks would likely require the ability to send malformed FireWire packets or otherwise trigger the error path, suggesting a local or device‑level attack vector. Given these constraints, the overall risk is moderate but mitigable by applying the kernel patch.

Generated by OpenCVE AI on September 19, 2026 at 03:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the FireWire patch (commit 05bfb1327dc5fb61528bab31cd8f0c1e4bddec23).
  • Disable the FireWire subsystem (e.g., by removing or blacklisting the firewire module) if the kernel cannot be updated immediately.
  • Restart the system after applying the patch or disabling the module to ensure that no leaked nodes remain allocated.

Generated by OpenCVE AI on September 19, 2026 at 03:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firewire: core: fix memory leak in error path of build_tree() In the error path of build_tree(), node instances can remain in the local linked list when the function returns. Whenever an invalid value is detected in the self ID sequence, each allocated node instance is either an entry in the linked list or an entry in the ports array of its parent node. Therefore, the allocate node instances can be safely released by traversing the linked list from its head. Release the remaining node instances with for_each_fw_node() before returning to the caller.
Title firewire: core: fix memory leak in error path of build_tree()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:26.756Z

Reserved: 2026-09-11T19:38:34.793Z

Link: CVE-2026-90213

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:16.533

Modified: 2026-09-17T17:17:16.533

Link: CVE-2026-90213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:15:16Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime