CVE-2026-64376
CVE CVE-2026-64376EUVD EUVD-2026-48920Published 2026-07-25T08:50:27.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: firmware_loader: fix device reference leak in firmware_upload_register() firmware_upload_register() -> fw_create_instance() -> device_initialize() After fw_create_instance() succeeds, the lifetime of the embedded struct device is expected to be managed through the device core reference counting, since fw_create_instance() has already called device_initialize(). In firmware_upload_register(), if alloc_lookup_fw_priv() fails after fw_create_instance() succeeds, the code reaches free_fw_sysfs and frees fw_sysfs directly instead of releasing the device reference with put_device(). This may leave the reference count of the embedded struct device unbalanced, resulting in a refcount leak. The issue was identified by a static analysis tool I developed and confirmed by manual review. Fix this by using put_device(fw_dev) in the failure path and letting fw_dev_release() handle the final cleanup, instead of freeing the instance directly from the error path.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 97730bbb242cde22b7140acd202ffd88823886c9 <896df22ee57648b0c505bd76ddbc6b2341834696; 97730bbb242cde22b7140acd202ffd88823886c9 <2619b47a0c8114eef980a56ade7e3ef4b58eb384; patch: 6.18.39; patch: 7.1.4; 97730bbb242cde22b7140acd202ffd88823886c9 <517676ec7dfca064e08f94007a4abd21969de0a0; patch: 0; 97730bbb242cde22b7140acd202ffd88823886c9 <46d403da376a8b7c1187193294953816e1a8d7fe; patch: 7.2-rc1; patch: 6.1.178; patch: 6.6.145; 5.19; 97730bbb242cde22b7140acd202ffd88823886c9 <92f41769e5fd16bcd9ba97500d0517332e0a5b45; patch: 6.12.96; 97730bbb242cde22b7140acd202ffd88823886c9 <15432f19562fdb9199cce6d9fc24db12c71ed574
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.