CVE-2026-46109
Published: May 28, 2026
Modified: Jun 1, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: usb: ulpi: fix memory leak on ulpi_register() error paths Commit 01af542392b5 ("usb: ulpi: fix double free in ulpi_register_interface() error path") removed kfree(ulpi) from ulpi_register_interface() to fix a double-free when device_register() fails. But when ulpi_of_register() or ulpi_read_id() fail before device_register() is called, the ulpi allocation is leaked. Add kfree(ulpi) on both error paths to properly clean up the allocation.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 2f70ba9dae13a190673cc3f9b4aad52179738f60 - < 0c2c0c6820fe96fa4be0a0499f8d3f3321b9af6caffected ee248e6e941e4f2e634df2bd43e5f1ef810ab6df - < f1b855c00988a9cb41134cab7cf9faedba775dd9affected 272a9b26c336a295e4e209157fed809706c1b1f7 - < 7bd61ed0bf9f4f1f2673d489b3bda1555b48d054affected aaeae6533d77e6ed4def85baec01e2815ebbef61 - < b0c0d44adb55c66663886cb6e30ee92cbb0f5385affected 8763f8317bb389aded32a32b08f6751cfff657d2 - < be2c1d825f54277472c87019e82013ac534ddc4c+11 more versions |
Linux | Linux | affected 7.0unaffected 0 - < 7.0unaffected 5.10.258 - <= 5.10.*unaffected 5.15.209 - <= 5.15.*unaffected 6.1.175 - <= 6.1.*+5 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now