CVE-2026-72026

high

Description

In the Linux kernel, the following vulnerability has been resolved: irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure imsic_early_acpi_init() allocates a firmware node before setting up the IMSIC state. If imsic_setup_state() fails, the function returns without freeing the allocated fwnode. Free the fwnode and clear the global pointer on this error path, matching the cleanup already done when imsic_early_probe() fails. [ tglx: Use a common cleanup path instead of copying code around ]

References

https://git.kernel.org/stable/c/b321a046d7717225c07ba3f4b7b0a4758c2f9d58

https://git.kernel.org/stable/c/a5a367756926de1c21a013ea5ed7fc2219f4cb4f

https://git.kernel.org/stable/c/a27f17bad38c5fea3c73281517869af0089a0451

https://git.kernel.org/stable/c/1358126fbed104e5657955d3ba029b283687ba02

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-17

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.002