PT-2026-52356 · Linux · Linux

Published

2026-06-25

·

Updated

2026-06-25

·

CVE-2026-53261

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
devlink: Release nested relation on devlink free
devlink relation state is normally released from devl unregister(), which calls devlink rel put(). This misses devlink instances that get a nested relation before registration and then fail probe before devl register() is reached.
That flow can happen for SFs. The child devlink gets linked to its parent before registration, then a later probe error calls devlink free() directly. Since the instance was never registered, devl unregister() is not called and devlink->rel is leaked.
Release any pending relation from devlink free() as well. The registered path is unchanged because devl unregister() already clears devlink->rel before devlink free() runs.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-53261

Affected Products

Linux