Junglewise Threat Intelligence

CVE-2026-45883: Linux kernel resource leak in sca3000_probe

CVE-2026-45883 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A resource leak was identified in the Linux kernel's sca3000 accelerometer driver. This issue occurs when the system fails to properly release hardware interrupt resources during a failed device initialization. While primarily a stability concern, such leaks can eventually lead to system instability or resource exhaustion if triggered repeatedly.

Technical details

A resource leak exists in drivers/iio/accel/sca3000.c within the sca3000_probe() function. The driver requests a threaded IRQ using request_threaded_irq(), but if the subsequent call to iio_device_register() fails, the IRQ is not released before the function returns. This results in a leaked interrupt resource. The fix introduces a return value check for iio_device_register() and ensures the execution flow jumps to the error_free_irq label to properly clean up resources. This is a local vulnerability requiring the ability to trigger device probing, typically through hardware interaction or administrative actions.

Affected products

  • Linux Linux kernel All versions prior to the 2026 fix (specifically affecting the sca3000 driver)

Timeline

  • 2026-01-27: patched: Initial patch authored by Harshit Mogalapalli
  • 2026-05-27: disclosed: CVE-2026-45883 published

References

Related threats