CVE-2026-72026

Source
https://cve.org/CVERecord?id=CVE-2026-72026
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72026.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72026
Downstream
Published
2026-08-15T05:51:50.581Z
Modified
2026-08-16T03:48:30.914502560Z
Summary
irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
Details

In the Linux kernel, the following vulnerability has been resolved:

irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure

imsicearlyacpiinit() allocates a firmware node before setting up the IMSIC state. If imsicsetup_state() fails, the function returns without freeing the allocated fwnode.

Free the fwnode and clear the global pointer on this error path, matching the cleanup already done when imsicearlyprobe() fails.

[ tglx: Use a common cleanup path instead of copying code around ]

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72026.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
fbe826b1c10699a70b81a441fe47b817d1019f37
Fixed
a27f17bad38c5fea3c73281517869af0089a0451
Fixed
a5a367756926de1c21a013ea5ed7fc2219f4cb4f
Fixed
b321a046d7717225c07ba3f4b7b0a4758c2f9d58
Fixed
1358126fbed104e5657955d3ba029b283687ba02

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72026.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72026.json"