PatchSiren cyber security CVE debrief
CVE-2026-45875 Linux CVE debrief
A resource leak vulnerability exists in the Linux kernel's MFD Arizona driver. The wm5102_clear_write_sequencer() function may return an error and exit directly, bypassing the cleanup sequence and leaving regulators enabled. This results in a resource leak where regulators remain powered on when they should be released. The fix changes the direct return to jump to the err_reset label, ensuring proper resource cleanup occurs even when the write sequencer clearing operation fails.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-05-27
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-05-27
Who should care
System administrators running Linux kernels with MFD Arizona driver support, particularly on embedded systems or devices using the Cirrus Logic WM5102 audio codec. Cloud providers and IoT device manufacturers utilizing affected kernel versions should prioritize patching to prevent potential resource exhaustion from accumulated regulator leaks.
Technical summary
The MFD Arizona driver in the Linux kernel contains a resource leak vulnerability in the wm5102_clear_write_sequencer() function. When this helper function returns an error, the code previously returned directly without executing the cleanup sequence, leaving regulators enabled and causing a resource leak. The vulnerability affects systems using the WM5102 audio codec. The resolution changes the error handling path to jump to the err_reset label, ensuring proper regulator cleanup occurs regardless of whether the write sequencer clearing operation succeeds or fails. Patches have been applied to multiple stable kernel branches.
Defensive priority
medium
Recommended defensive actions
- Apply kernel patches from stable branches when available for your distribution
- Monitor distribution security advisories for kernel updates addressing CVE-2026-45875
- Review systems using WM5102 audio codec for potential resource exhaustion issues
- Consider rebooting affected systems after kernel update to ensure clean regulator state
Evidence notes
The vulnerability description indicates this is a resource leak in regulator management within the MFD Arizona driver. The issue occurs when wm5102_clear_write_sequencer() fails and returns directly without executing cleanup code. The fix involves changing error handling to use the err_reset label for proper resource deallocation. Multiple stable kernel branches received patches as indicated by the git.kernel.org references.
Official resources
-
CVE-2026-45875 CVE record
CVE.org
-
CVE-2026-45875 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
2026-05-27