← Back to CVE intelligence
CVE intelligence

CVE-2026-53261

Vulnerability intelligence

Published Jun 25, 2026Sources checked Oct 8, 2026
5.5MEDIUMCVSS out of 10
What this means

Review the available evidence

CVE-2026-53261 and is rated Medium severity with a CVSS score of 5.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

What to do next

Remediation and response

Ubuntu Security Notices guidance

Vendor revision: Oct 8, 2026
Vendor remediation details

This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - MIPS architecture; - x86 architecture; - Intel NPU Driver; - Auxiliary display drivers; - Compressed RAM block device driver; - GPIO subsystem; - GPU drivers; - HID subsystem; - I2C subsystem; - IIO subsystem; - InfiniBand drivers; - Input Device core drivers; - Input Device (Mouse) drivers; - Multiple devices driver; - Media drivers; - Fastrpc Driver; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - Microsoft Azure Network Adapter (MANA) driver; - Texas Instruments network drivers; - NVMEM (Non Volatile Memory) drivers; - Parport drivers; - SCSI subsystem; - SLIMbus drivers; - NVIDIA Tegra SoC drivers; - SPI subsystem; - Trusted Execution Environment drivers; -

Ubuntu Security Notices guidance

Vendor revision: Oct 8, 2026
Vendor remediation details

This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - MIPS architecture; - x86 architecture; - Intel NPU Driver; - Auxiliary display drivers; - Compressed RAM block device driver; - GPIO subsystem; - GPU drivers; - HID subsystem; - I2C subsystem; - IIO subsystem; - InfiniBand drivers; - Input Device core drivers; - Input Device (Mouse) drivers; - Multiple devices driver; - Media drivers; - Fastrpc Driver; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - Microsoft Azure Network Adapter (MANA) driver; - Texas Instruments network drivers; - NVMEM (Non Volatile Memory) drivers; - Parport drivers; - SCSI subsystem; - SLIMbus drivers; - NVIDIA Tegra SoC drivers; - SPI subsystem; - Trusted Execution Environment drivers; -

Ubuntu Security Notices guidance

Vendor revision: Oct 8, 2026
Vendor remediation details

This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - MIPS architecture; - x86 architecture; - Intel NPU Driver; - Auxiliary display drivers; - Compressed RAM block device driver; - GPIO subsystem; - GPU drivers; - HID subsystem; - I2C subsystem; - IIO subsystem; - InfiniBand drivers; - Input Device core drivers; - Input Device (Mouse) drivers; - Multiple devices driver; - Media drivers; - Fastrpc Driver; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - Microsoft Azure Network Adapter (MANA) driver; - Texas Instruments network drivers; - NVMEM (Non Volatile Memory) drivers; - Parport drivers; - SCSI subsystem; - SLIMbus drivers; - NVIDIA Tegra SoC drivers; - SPI subsystem; - Trusted Execution Environment drivers; -

CISA KEVNot listedBased on the latest collected catalog
EPSS0.1%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-53261?

In the Linux kernel, the following vulnerability has been resolved:

devlink: Release nested relation on devlink free

devlink relation state is normally released from devl_unregister(), which calls devlink_rel_put(). This misses devlink instances that get a nested relation before registration and then fail probe before devl_register() is reached.

That flow can happen for SFs. The child devlink gets linked to its parent before registration, then a later probe error calls devlink_free() directly.

Since the instance was never registered, devl_unregister() is not called and devlink->rel is leaked.

Release any pending relation from devlink_free() as well. The registered path is unchanged because devl_unregister() already clears devlink->rel before devlink_free() runs.

Source: NVD