Junglewise Threat Intelligence

CVE-2026-72026: Linux kernel RISCV IMSIC firmware node resource leak

CVE-2026-72026 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RISCV IMSIC interrupt handling driver fails to properly release a firmware node resource when initialization fails. A system administrator or developer who triggers this error path during early boot could cause memory to leak and potentially degrade system stability over time, though this is a low-impact initialization bug rather than a security vulnerability.

Technical details

This is a resource-leak vulnerability (CWE-401) in the RISCV IMSIC early ACPI initialization code. The function imsic_early_acpi_init() allocates a firmware node via irq_domain_alloc_fwnode() but fails to free it when imsic_setup_state() returns an error. The vulnerable code path is triggered during kernel early boot on RISCV systems with ACPI-based IMSIC configuration. The fix introduces a common cleanup label that properly releases the firmware node and clears the global pointer in all error paths. No exploitation in the wild has been reported; this is a code quality/reliability fix.

Affected products

  • Linux Linux Kernel affected versions include multiple stable kernel series

Timeline

  • 2026-06-23: disclosed
  • 2026-06-30: patched

References

Related threats