Junglewise Threat Intelligence

CVE-2026-90352: Linux kernel mt76 mt7915 resource leak on probe IRQ failure

CVE-2026-90352 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's MT7915 WiFi driver fails to properly release a hardware interface reference when interrupt setup fails during device initialization. This causes a resource leak that could lead to memory exhaustion over time if device initialization is repeatedly attempted, potentially affecting system stability.

Technical details

A resource leak exists in the MT7915 PCI probe function (mt7915_pci_probe) where the hif2 reference obtained from mt7915_pci_init_hif2() is not released if pci_alloc_irq_vectors() or the subsequent devm_request_irq() call fails. The original code only released this reference through code paths that check dev->hif2, which is assigned after IRQ setup. The fix explicitly calls mt7915_put_hif2() on the two error paths where the reference would otherwise leak. This is a local issue affecting kernel stability with no remote attack vector.

Affected products

  • Linux Linux kernel prior to commit 8370aebd26a9dfa2e0de665e3ab504c0e97ee730

Timeline

  • 2026-09-17: disclosed
  • 2026-07-27: patched: Upstream fix commit 8370aebd26a9dfa2e0de665e3ab504c0e97ee730

References

Related threats