---
id: CVE-2026-64376
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  firmware_loader: fix device reference leak in firmware_upload_register()

  firmware_upload_register()
    -> fw_create_instance()
       -> device_initialize()

  After fw_cre…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  firmware_loader: fix device reference leak in firmware_upload_register()

  firmware_upload_register()
    -> fw_create_instance()
       -> device_initialize()

  After fw_cre…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.19, < 6.1.178'
  - 'linux_kernel >= 6.2, < 6.6.145'
  - 'linux_kernel >= 6.7, < 6.12.96'
  - 'linux_kernel >= 6.13, < 6.18.39'
  - 'linux_kernel >= 6.19, < 7.1.4'
patched:
  - linux_kernel 7.1.4
published: '2026-07-25'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T14:21:55.037'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64376'
references:
  - url: 'https://git.kernel.org/stable/c/15432f19562fdb9199cce6d9fc24db12c71ed574'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2619b47a0c8114eef980a56ade7e3ef4b58eb384'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/46d403da376a8b7c1187193294953816e1a8d7fe'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/517676ec7dfca064e08f94007a4abd21969de0a0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/896df22ee57648b0c505bd76ddbc6b2341834696'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/92f41769e5fd16bcd9ba97500d0517332e0a5b45'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-64376.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-64376'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2507205'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-64376'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64376'
  - url: >-
      https://lore.kernel.org/linux-cve-announce/2026072524-CVE-2026-64376-efcf@gregkh/T
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.00123
epssPercentile: 0.02329
ingestedAt: '2026-09-08T15:33:26.948Z'
cwe:
  - CWE-911
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

firmware_loader: fix device reference leak in firmware_upload_register()

firmware_upload_register()
  -> fw_create_instance()
     -> device_initialize()

After fw_create_instance() succeeds, the lifetime of the embedded struct
device is expected to be managed through the device core reference
counting, since fw_create_instance() has already called
device_initialize().

In firmware_upload_register(), if alloc_lookup_fw_priv() fails after
fw_create_instance() succeeds, the code reaches free_fw_sysfs and frees
fw_sysfs directly instead of releasing the device reference with
put_device(). This may leave the reference count of the embedded struct
device unbalanced, resulting in a refcount leak.

The issue was identified by a static analysis tool I developed and
confirmed by manual review. Fix this by using put_device(fw_dev) in the
failure path and letting fw_dev_release() handle the final cleanup,
instead of freeing the instance directly from the error path.

## Affected

- `linux_kernel >= 5.19, < 6.1.178`
- `linux_kernel >= 6.2, < 6.6.145`
- `linux_kernel >= 6.7, < 6.12.96`
- `linux_kernel >= 6.13, < 6.18.39`
- `linux_kernel >= 6.19, < 7.1.4`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.1.4`

## Vendor advisories

- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-64376.json)
