Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: asus-wmi: fix resource leaks on probe failure

During driver initialization in asus_wmi_add(), various subsystems are
registered sequentially. However, the error path labels are out of order
relative to the registration sequence.

Specifically:
1. If asus_wmi_custom_fan_curve_init() fails, the driver jumps to
fail_custom_fan_curve. Because this label is placed below fail_sysfs,
it bypasses the cleanup calls for the input device and sysfs groups,
which were successfully registered before, leaking those resources.
2. If asus_screenpad_init() fails, the driver jumps to fail_screenpad.
Because fail_screenpad is placed below fail_backlight, it bypasses the
cleanup calls for backlight and rfkill, leaking those resources.

Fix these resource leaks by reordering the error path labels in
asus_wmi_add() to match the exact reverse order of the resource
allocations.
Published: 2026-09-17
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak (potential Denial of Service)
Action: Apply Patch
AI Analysis

Impact

The asus_wmi driver in the Linux kernel fails to clean up previously allocated resources when initialization errors occur. The issue involves multiple subsystems such as input devices, sysfs groups, backlights, rfkill, and screenpad devices. Because the error handling labels are out of order, cleanup for earlier registrations is bypassed, leaking kernel memory and device handles. Although the immediate impact is not code execution, repeated failures can exhaust limited kernel resources, potentially leading to a denial of service or weakening system stability.

Affected Systems

Any Linux kernel build that includes the unpatched Asus WMI driver is affected, including mainstream distributions that ship the kernel with asus_wmi. The specific kernel versions are not enumerated in the data, so a vendor’s default kernel may be impacted if it contains the original driver code prior to the fix.

Risk and Exploitability

The CVSS score of 7 denotes high severity, while the EPSS score of less than 1 % indicates a low probability of exploitation at present. Based on the description, it is inferred that an attacker would need local access to trigger a probe failure during driver initialization, for example by manipulating device attachment or kernel loading procedures. The risk is principally resource exhaustion, which could degrade system availability if an attacker causes repeated failures. The vulnerability is not listed in CISA’s KEV catalog, suggesting no public exploits have been observed.

Generated by OpenCVE AI on September 24, 2026 at 03:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel that includes the asus_wmi driver fix.
  • If an immediate kernel update is not possible, disable the asus_wmi module by blacklisting it in /etc/modprobe.d or using systemctl to stop the module.
  • After applying the update or disabling the module, reboot the system so that any leaked resources are released.

Generated by OpenCVE AI on September 24, 2026 at 03:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-744

Thu, 24 Sep 2026 00:15:00 +0000


Sun, 20 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-744

Sun, 20 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754

Sat, 19 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754

Sat, 19 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754

Sat, 19 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: fix resource leaks on probe failure During driver initialization in asus_wmi_add(), various subsystems are registered sequentially. However, the error path labels are out of order relative to the registration sequence. Specifically: 1. If asus_wmi_custom_fan_curve_init() fails, the driver jumps to fail_custom_fan_curve. Because this label is placed below fail_sysfs, it bypasses the cleanup calls for the input device and sysfs groups, which were successfully registered before, leaking those resources. 2. If asus_screenpad_init() fails, the driver jumps to fail_screenpad. Because fail_screenpad is placed below fail_backlight, it bypasses the cleanup calls for backlight and rfkill, leaking those resources. Fix these resource leaks by reordering the error path labels in asus_wmi_add() to match the exact reverse order of the resource allocations.
Title platform/x86: asus-wmi: fix resource leaks on probe failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:01.700Z

Reserved: 2026-09-17T16:02:15.086Z

Link: CVE-2026-93116

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:06.200

Modified: 2026-09-18T18:18:21.310

Link: CVE-2026-93116

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-17T00:00:00Z

Links: CVE-2026-93116 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T03:30:08Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime