CVE-2026-45883
📛 CVE Title
iio: sca3000: Fix a resource leak in sca3000_probe()
Description
In the Linux kernel, the following vulnerability has been resolved: iio: sca3000: Fix a resource leak in sca3000_probe() spi->irq from request_threaded_irq() not released when iio_device_register() fails. Add an return value check and jump to a common error handler when iio_device_register() fails.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Linux
- CVSS severity
- high
- CVSS score
- 8.4 / 10
- CVSS vector
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Effective score
- 8.4 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- 2026-05-13
- Published
- 2026-05-27 12:16 UTC
- Last updated
- 2026-05-27 12:16 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/45xxx/CVE-2026-45883.json
- Linked Threat
- CVE-2026-45883 — CVE-2026-45883
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-27 14:17:02 UTC
- NVD last modified
- 2026-06-25 21:12:29 UTC
- NVD CVSS v3.1
- 5.5 / 10 MEDIUM source: nvd@nist.gov
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 3.6 / 10
- EPSS score
- 0.0016 (probability of exploitation in next 30 days)
- EPSS percentile
- 5.17% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26
NVD-assigned CWE(s):
CWE-401
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-07-27 11:54 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-32349 - Assigner
- Linux
- Published
- May 27, 2026, 12:16:55 PM
- Updated
- May 27, 2026, 12:16:55 PM
- EUVD base score
- 0.0 / 10
- EUVD-reported EPSS
- 0.1600
- Vendors
- Linux
- Products
-
Linux (patch: 7.0)Linux (9a4936dc89a34e002946a6c08b330918ec6afab8 <597d749c5180f3e351837e851a6131b140324e9f)Linux (patch: 6.6.128)Linux (9a4936dc89a34e002946a6c08b330918ec6afab8 <55e13abf22c27a3b0ab5cf941dd07a2d9786736c)Linux (9a4936dc89a34e002946a6c08b330918ec6afab8 <e8e960c3d23fdb4882d70d34ce762368da0f1427)Linux (9a4936dc89a34e002946a6c08b330918ec6afab8 <517d9f2b963089b3d64c23accf7920d77f5a30c8)Linux (9a4936dc89a34e002946a6c08b330918ec6afab8 <62b44ebc1f2c71db3ca2d4737c52e433f6f03038)Linux (patch: 6.18.14)Linux (9a4936dc89a34e002946a6c08b330918ec6afab8 <103ac8e3a7f345a0966ef582b8a874ac31a92c7c)Linux (9a4936dc89a34e002946a6c08b330918ec6afab8 <84d3c396d8ae73c24dececfcc4e544ea09311e32)Linux (9a4936dc89a34e002946a6c08b330918ec6afab8 <40c860ece22542178cddcf01b08644bcdbc597b3)Linux (patch: 6.19.4)Linux (patch: 5.10.252)Linux (patch: 6.12.75)Linux (patch: 0)Linux (patch: 5.15.202)Linux (4.10)Linux (patch: 6.1.165)
- Aliases
-
GHSA-mjh6-2qq4-fp8m
ENISA description: In the Linux kernel, the following vulnerability has been resolved: iio: sca3000: Fix a resource leak in sca3000_probe() spi->irq from request_threaded_irq() not released when iio_device_register() fails. Add an return value check and jump to a common error handler when iio_device_register() fails.
EUVD references (8)
- https://git.kernel.org/stable/c/55e13abf22c27a3b0ab5cf941dd07a2d9786736c
- https://git.kernel.org/stable/c/40c860ece22542178cddcf01b08644bcdbc597b3
- https://git.kernel.org/stable/c/597d749c5180f3e351837e851a6131b140324e9f
- https://git.kernel.org/stable/c/e8e960c3d23fdb4882d70d34ce762368da0f1427
- https://git.kernel.org/stable/c/103ac8e3a7f345a0966ef582b8a874ac31a92c7c
- https://git.kernel.org/stable/c/517d9f2b963089b3d64c23accf7920d77f5a30c8
- https://git.kernel.org/stable/c/84d3c396d8ae73c24dececfcc4e544ea09311e32
- https://git.kernel.org/stable/c/62b44ebc1f2c71db3ca2d4737c52e433f6f03038
Affected products (2)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Linux | Linux |
9a4936dc89a34e002946a6c08b330918ec6afab8 (affected),
9a4936dc89a34e002946a6c08b330918ec6afab8 (affected),
9a4936dc89a34e002946a6c08b330918ec6afab8 (affected),
9a4936dc89a34e002946a6c08b330918ec6afab8 (affected),
9a4936dc89a34e002946a6c08b330918ec6afab8 (affected),
9a4936dc89a34e002946a6c08b330918ec6afab8 (affected),
9a4936dc89a34e002946a6c08b330918ec6afab8 (affected),
9a4936dc89a34e002946a6c08b330918ec6afab8 (affected)
|
— |
| Linux | Linux |
4.10 (affected),
0 (unaffected),
5.10.252 (unaffected),
5.15.202 (unaffected),
6.1.165 (unaffected),
6.6.128 (unaffected),
6.12.75 (unaffected),
6.18.14 (unaffected),
6.19.4 (unaffected),
7.0 (unaffected)
|
— |
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendor references (8)
References embedded in the original CVE record by the assigning CNA.
- https://git.kernel.org/stable/c/55e13abf22c27a3b0ab5cf941dd07a2d9786736c
- https://git.kernel.org/stable/c/40c860ece22542178cddcf01b08644bcdbc597b3
- https://git.kernel.org/stable/c/597d749c5180f3e351837e851a6131b140324e9f
- https://git.kernel.org/stable/c/e8e960c3d23fdb4882d70d34ce762368da0f1427
- https://git.kernel.org/stable/c/103ac8e3a7f345a0966ef582b8a874ac31a92c7c
- https://git.kernel.org/stable/c/517d9f2b963089b3d64c23accf7920d77f5a30c8
- https://git.kernel.org/stable/c/84d3c396d8ae73c24dececfcc4e544ea09311e32
- https://git.kernel.org/stable/c/62b44ebc1f2c71db3ca2d4737c52e433f6f03038
Web references (11)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://git.kernel.org/stable/c/103ac8e3a7f345a0966ef582b8a874ac31a92c7c tenable:git.kernel.org
- https://git.kernel.org/stable/c/40c860ece22542178cddcf01b08644bcdbc597b3 tenable:git.kernel.org
- https://git.kernel.org/stable/c/517d9f2b963089b3d64c23accf7920d77f5a30c8 tenable:git.kernel.org
- https://git.kernel.org/stable/c/55e13abf22c27a3b0ab5cf941dd07a2d9786736c tenable:git.kernel.org
- https://git.kernel.org/stable/c/597d749c5180f3e351837e851a6131b140324e9f tenable:git.kernel.org
- https://git.kernel.org/stable/c/62b44ebc1f2c71db3ca2d4737c52e433f6f03038 tenable:git.kernel.org
- https://git.kernel.org/stable/c/84d3c396d8ae73c24dececfcc4e544ea09311e32 tenable:git.kernel.org
- https://git.kernel.org/stable/c/e8e960c3d23fdb4882d70d34ce762368da0f1427 tenable:git.kernel.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-45883 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45883 tenable:www.cve.org
- https://www.first.org/epss/ tenable:www.first.org
NVD-tagged references (8)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://git.kernel.org/stable/c/103ac8e3a7f345a0966ef582b8a874ac31a92c7c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/40c860ece22542178cddcf01b08644bcdbc597b3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/517d9f2b963089b3d64c23accf7920d77f5a30c8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/55e13abf22c27a3b0ab5cf941dd07a2d9786736c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/597d749c5180f3e351837e851a6131b140324e9f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/62b44ebc1f2c71db3ca2d4737c52e433f6f03038 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/84d3c396d8ae73c24dececfcc4e544ea09311e32 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/e8e960c3d23fdb4882d70d34ce762368da0f1427 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:blog.gridinsoft.com
CVE - 2026 -41089 in Windows Netlogon is now reported as actively exploited. Patch domain controllers and check LSASS, Netlogon, and authentication logs.
2026-06-04 00:16 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-04 00:16 UTC -
web:securityarsenal.com
A critical CVSS 9.8 flaw in Windows Netlogon allows SYSTEM-level code execution on Domain Controllers. Immediate patching is required.
2026-06-04 00:16 UTC -
web:techdocs.broadcom.com
Patch Category Security Patch Severity Critical Host Reboot Required Yes Virtual Machine Migration or Shutdown Required Yes Affected Hardware N/A Affected Software N/A Affected VIBs Included VMware_bootbank_esxio-update_8..3-.60.24585383 VMware_bootbank_loadesxio_8..3-.60.24585383 PRs Fixed N/A CVE numbers N/A Due to their dependency on the ...
2026-06-04 00:16 UTC -
web:windowsforum.com
The mitigation name administrators should verify for CVE - 2026 -42897 is M2. Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition are affected at any update level, while Exchange Online is not affected.
2026-06-04 00:16 UTC -
web:windowsreport.com
Belgium's cybersecurity agency warns attackers are actively exploiting the critical Windows Netlogon vulnerability CVE - 2026 -41089.
2026-06-04 00:16 UTC -
web:www.csoonline.com
Microsoft highlighted six new and actively exploited vulnerabilities among the 60 fixes issued in today's February Patch Tuesday releases.
2026-06-04 00:16 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-06-04 00:16 UTC -
web:www.rapid7.com
Microsoft is publishing 137 vulnerabilities on May 2026 Patch Tuesday, including critical RCE in Netlogon and the Windows DNS client.
2026-06-04 00:16 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-06-04 00:16 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-06-19 02:27 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-06-19 02:27 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-06-19 02:27 UTC -
web:windowsforum.com
For CVE - 2026 -45583, administrators should verify the status of Exchange health tooling, mitigation services, and update readiness rather than assuming protection exists because a feature name sounds reassuring.
2026-06-19 02:27 UTC -
web:www.cisa.gov
This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency's Emergency Directive 25-02: Mitigate Microsoft Exchange Vulnerability. Section 3553 (h) of title 44, U.S. Code, authorizes the Secretary of Homeland Security, in response to a known or reasonably suspected information security threat, vulnerability, or incident that represents a substantial ...
2026-06-19 02:27 UTC -
web:www.crowdstrike.com
Microsoft has released security updates for 130 vulnerabilities, including 30 critical, in its May 2026 Patch Tuesday rollout.
2026-06-19 02:27 UTC -
web:www.forbes.com
Updated May 18: This article has been updated to include further details on the emergency mitigation process recommended by Microsoft after the CVE - 2026 -42897 Exchange Server zero-day was ...
2026-06-19 02:27 UTC -
web:www.rapid7.com
Microsoft is publishing 200 vulnerabilities on June 2026 Patch Tuesday, including an HTTP/2 denial of service vulnerability and an elevation of privilege vulnerability in PowerToys.
2026-06-19 02:27 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-45883.json.
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/iio/accel/sca3000.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "55e13abf22c27a3b0ab5cf941dd07a2d9786736c",
"status": "affected",
"version": "9a4936dc89a34e002946a6c08b330918ec6afab8",
"versionType": "git"
},
{
"lessThan": "40c860ece22542178cddcf01b08644bcdbc597b3",
"status": "affected",
"version": "9a4936dc89a34e002946a6c08b330918ec6afab8",
"versionType": "git"
},
{
"lessThan": "597d749c5180f3e351837e851a6131b140324e9f",
"status": "affected",
"version": "9a4936dc89a34e002946a6c08b330918ec6afab8",
"versionType": "git"
},
{
"lessThan": "e8e960c3d23fdb4882d70d34ce762368da0f1427",
"status": "affected",
"version": "9a4936dc89a34e002946a6c08b330918ec6afab8",
"versionType": "git"
},
{
"lessThan": "103ac8e3a7f345a0966ef582b8a874ac31a92c7c",
"status": "affected",
"version": "9a4936dc89a34e002946a6c08b330918ec6afab8",
"versionType": "git"
},
{
"lessThan": "517d9f2b963089b3d64c23accf7920d77f5a30c8",
"status": "affected",
"version": "9a4936dc89a34e002946a6c08b330918ec6afab8",
"versionType": "git"
},
{
"lessThan": "84d3c396d8ae73c24dececfcc4e544ea09311e32",
"status": "affected",
"version": "9a4936dc89a34e002946a6c08b330918ec6afab8",
"versionType": "git"
},
{
"lessThan": "62b44ebc1f2c71db3ca2d4737c52e433f6f03038",
"status": "affected",
"version": "9a4936dc89a34e002946a6c08b330918ec6afab8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/iio/accel/sca3000.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"lessThan": "4.10",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.252",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.202",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.165",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.252",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.202",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.165",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.14",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "4.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "4.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: sca3000: Fix a resource leak in sca3000_probe()\n\nspi->irq from request_threaded_irq() not released when\niio_device_register() fails. Add an return value check and jump to a\ncommon error handler when iio_device_register() fails."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-27T12:16:55.840Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/55e13abf22c27a3b0ab5cf941dd07a2d9786736c"
},
{
"url": "https://git.kernel.org/stable/c/40c860ece22542178cddcf01b08644bcdbc597b3"
},
{
"url": "https://git.kernel.org/stable/c/597d749c5180f3e351837e851a6131b140324e9f"
},
{
"url": "https://git.kernel.org/stable/c/e8e960c3d23fdb4882d70d34ce762368da0f1427"
},
{
"url": "https://git.kernel.org/stable/c/103ac8e3a7f345a0966ef582b8a874ac31a92c7c"
},
{
"url": "https://git.kernel.org/stable/c/517d9f2b963089b3d64c23accf7920d77f5a30c8"
},
{
"url": "https://git.kernel.org/stable/c/84d3c396d8ae73c24dececfcc4e544ea09311e32"
},
{
"url": "https://git.kernel.org/stable/c/62b44ebc1f2c71db3ca2d4737c52e433f6f03038"
}
],
"title": "iio: sca3000: Fix a resource leak in sca3000_probe()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-45883",
"datePublished": "2026-05-27T12:16:55.840Z",
"dateReserved": "2026-05-13T15:03:33.082Z",
"dateUpdated": "2026-05-27T12:16:55.840Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}