Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93136— bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: 总线:MHI:EP:修复 MHI 设备创建过程中错误路径下的设备引用计数泄漏问题 在 函数中,分配传输设备后,会分别获取一个用于上行(UL)通道的设备引用和一个用于下行(DL)通道的设备引用。通常情况下,这些引用会在 中、设备自身被移除之前释放。 然而,如果 或 调用失败,当前的错误处理路径仅释放了一个引用。剩余未释放的通道引用会导致设备无法被正确释放,并使这些通道关联到一个从未成功注册的设备上。 修复方法是:将上述两种失败情况统一引导至一个共同的回退(unwind)路

AI Predicted 3.1 Difficulty: Hard EPSS 0.21% · P11

Possible ATT&CK Techniques 1 AI

T1673 · Virtual Machine Discovery

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux 297c77a0f27312b9a04696018c4cbd47926ca92b< 8acc3813ab5015af73eeb74c9032443162f122d1 affected
297c77a0f27312b9a04696018c4cbd47926ca92b< 51ddb831a36102fd0ea25f354935e49abce9f0a1 affected
297c77a0f27312b9a04696018c4cbd47926ca92b< 4fae8fd4adc7f4765463ddeb1a5fad23936432f6 affected
297c77a0f27312b9a04696018c4cbd47926ca92b< 5587e7871ce994bb079f97fe7e430d99627e5292 affected
297c77a0f27312b9a04696018c4cbd47926ca92b< 8f3f64faee335eb678fd7dca7b95dfe3d0b271fd affected
297c77a0f27312b9a04696018c4cbd47926ca92b< 6f12862600bb70e599a614d706a095ea5f8f9858 affected
5.19 affected
< 5.19 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93136

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation mhi_ep_create_device() takes one device reference for the UL channel and another for the DL channel after allocating the transfer device. These references are normally released by mhi_ep_destroy_device() before the device itself is removed. If dev_set_name() or device_add() fails, the error path currently drops only one reference. The remaining channel references keep the device from being released and leave the channels associated with a device that was never registered. Route both failures through a common unwind path that drops the DL channel reference, the UL channel reference, and the initial reference from device_initialize().
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 297c77a0f27312b9a04696018c4cbd47926ca92b ~ 8acc3813ab5015af73eeb74c9032443162f122d1 -
Linux Linux 5.19 -

II. Public POCs for CVE-2026-93136

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93136

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-93136 (6)

Same Patch Batch · Linux · 2026-09-17 · 600 CVEs total

CVE-2026-92489 9.8 CRITICAL xfrm: Fix skb double-free in xfrm_dev_direct_output()
CVE-2026-90151 9.8 CRITICAL NFSv4: remove callback IDR entry on client allocation failure
CVE-2026-90235 9.8 CRITICAL sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE
CVE-2026-90104 9.8 CRITICAL NFSv4.1: zero referring call lists before decoding
CVE-2026-90173 9.8 CRITICAL smb: smbdirect: free completion queues with ib_free_cq()
CVE-2026-90110 9.4 CRITICAL inetpeer: randomize RB-tree node comparison using SipHash
CVE-2026-90230 9.1 CRITICAL nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
CVE-2026-90413 9.1 CRITICAL IB/isert: reject login PDUs declaring more data than was received
CVE-2026-90414 9.1 CRITICAL IB/isert: reject PDUs declaring more data than was received
CVE-2026-90425 8.8 HIGH iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID
CVE-2026-93042 8.8 HIGH dmaengine: dw-edma: Terminate all descriptors without callbacks
CVE-2026-93189 8.8 HIGH HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
CVE-2026-90329 8.8 HIGH HID: synchronize input before cleaning up a failed probe
CVE-2026-90357 8.8 HIGH wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
CVE-2026-90256 8.8 HIGH Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind
CVE-2026-90367 8.8 HIGH wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
CVE-2026-90381 8.8 HIGH wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
CVE-2026-90379 8.8 HIGH wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash
CVE-2026-90380 8.8 HIGH wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
CVE-2026-90371 8.8 HIGH wifi: mt76: fix RXDMAD_C buffer recycling race

Showing top 20 of 600 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-93136

No comments yet


Leave a comment