In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix leakage in __construct_region() Failing the first sysfs_update_group() needs to explicitly kfree the resource as it is too early for cxl_region_iomem_release() to do so.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31529-f32e@gregkh/T