tpm: st33zp24: Fix missing cleanup on get_burstcount() error
Summary
| CVE | CVE-2026-45871 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-27 14:17:00 UTC |
| Updated | 2026-05-27 14:48:31 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: tpm: st33zp24: Fix missing cleanup on get_burstcount() error get_burstcount() can return -EBUSY on timeout. When this happens, st33zp24_send() returns directly without releasing the locality acquired earlier. Use goto out_err to ensure proper cleanup when get_burstcount() fails. |
Risk And Classification
EPSS: 0.000240000 probability, percentile 0.073320000 (date 2026-06-01)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected bf38b8710892333cec2d8069644eb36ff435fd6f e0ce3da82341fcd6194175f1837946b2a894c625 git | Not specified |
| CNA | Linux | Linux | affected bf38b8710892333cec2d8069644eb36ff435fd6f 7687133509cf66ced120b667fefd21f80bf17993 git | Not specified |
| CNA | Linux | Linux | affected bf38b8710892333cec2d8069644eb36ff435fd6f 1256c6dc96d1e687e6e9b63088156ed07411b00c git | Not specified |
| CNA | Linux | Linux | affected bf38b8710892333cec2d8069644eb36ff435fd6f a51cff9be046e13e1c1b2fe45d5c48b582ec9b8c git | Not specified |
| CNA | Linux | Linux | affected bf38b8710892333cec2d8069644eb36ff435fd6f cc09d55f519e15355de343264a22ac6682b8305e git | Not specified |
| CNA | Linux | Linux | affected bf38b8710892333cec2d8069644eb36ff435fd6f ec15eb67fe9df87981b4829b901ec254273ca483 git | Not specified |
| CNA | Linux | Linux | affected bf38b8710892333cec2d8069644eb36ff435fd6f 4fffb77d35d038f146e6192da583dbe4971d869e git | Not specified |
| CNA | Linux | Linux | affected bf38b8710892333cec2d8069644eb36ff435fd6f 3e91b44c93ad2871f89fc2a98c5e4fe6ca5db3d9 git | Not specified |
| CNA | Linux | Linux | affected 4.1 | Not specified |
| CNA | Linux | Linux | unaffected 4.1 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.252 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.202 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.165 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.128 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.75 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.14 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.19.4 6.19.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/1256c6dc96d1e687e6e9b63088156ed07411b00c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/3e91b44c93ad2871f89fc2a98c5e4fe6ca5db3d9 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7687133509cf66ced120b667fefd21f80bf17993 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e0ce3da82341fcd6194175f1837946b2a894c625 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ec15eb67fe9df87981b4829b901ec254273ca483 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a51cff9be046e13e1c1b2fe45d5c48b582ec9b8c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4fffb77d35d038f146e6192da583dbe4971d869e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/cc09d55f519e15355de343264a22ac6682b8305e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.