Junglewise Threat Intelligence

CVE-2026-63861: Linux Kernel MediaTek SPI NAND ECC engine resource leak

CVE-2026-63861 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A resource management issue was identified in the Linux kernel's MediaTek SPI NAND Flash Interface driver. The system was failing to properly shut down the Error Correction Code (ECC) engine when the driver failed to start or was removed. This could lead to system instability or resource leaks on devices using this specific hardware interface.

Technical details

A vulnerability in the MediaTek SPI NAND Flash Interface (mtk-snfi) driver in the Linux kernel stemmed from missing teardown logic in the mtk_snand_probe() function. While the driver successfully registered the on-host NAND ECC engine, it lacked the corresponding unregistration call (nand_ecc_unregister_on_host_hw_engine) in its error handling paths and removal callback. This resulted in a resource leak and potential kernel instability. The fix introduces a devm-managed cleanup action (devm_add_action_or_reset) to ensure the ECC engine is automatically and safely unregistered during probe failures or device removal.

Affected products

  • Linux Linux 5.19 to 6.1.175, 6.6.141, 6.12.91, 6.18.33, 7.0.10

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References