In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8183: Release reserved memory on cleanup The MT8183 AFE probe… (CVE-2026-72258)
A vulnerability in the Linux kernel's ASoC Mediatek mt8183 driver involved reserved memory not being released on driver removal or probe failures. This issue was fixed by registering a devm cleanup action to ensure consistent release of reserved memory, aligning with newer Mediatek AFE drivers.
AI Analysis
Technical Summary
The Linux kernel's ASoC Mediatek mt8183 audio driver assigned reserved memory using of_reserved_mem_device_init(), but failed to release this memory upon driver removal or probe failure. This could lead to resource leakage. The fix involved adding a devm cleanup action to reliably release the reserved memory, matching the behavior of newer Mediatek AFE drivers.
Potential Impact
The vulnerability could cause reserved memory to remain allocated after driver removal or failed initialization, potentially leading to resource leakage and system instability. There is no indication of direct security compromise or exploitation in the wild.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to register a devm cleanup action that releases the reserved memory consistently. Users should update to the fixed kernel version containing this patch. Patch status is not explicitly confirmed in the provided data; verify with the official Linux kernel advisories or vendor updates for the exact fixed versions.
In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8183: Release reserved memory on cleanup The MT8183 AFE probe… (CVE-2026-72258)
Description
A vulnerability in the Linux kernel's ASoC Mediatek mt8183 driver involved reserved memory not being released on driver removal or probe failures. This issue was fixed by registering a devm cleanup action to ensure consistent release of reserved memory, aligning with newer Mediatek AFE drivers.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's ASoC Mediatek mt8183 audio driver assigned reserved memory using of_reserved_mem_device_init(), but failed to release this memory upon driver removal or probe failure. This could lead to resource leakage. The fix involved adding a devm cleanup action to reliably release the reserved memory, matching the behavior of newer Mediatek AFE drivers.
Potential Impact
The vulnerability could cause reserved memory to remain allocated after driver removal or failed initialization, potentially leading to resource leakage and system instability. There is no indication of direct security compromise or exploitation in the wild.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to register a devm cleanup action that releases the reserved memory consistently. Users should update to the fixed kernel version containing this patch. Patch status is not explicitly confirmed in the provided data; verify with the official Linux kernel advisories or vendor updates for the exact fixed versions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-x87g-g4xm-27f5
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-72258"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a808b72bf8831d5394fcf89
Added to database: 08/15/2026, 15:53:22 UTC
Last enriched: 08/15/2026, 16:43:22 UTC
Last updated: 08/15/2026, 16:43:22 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.