staging: vme_user: fix location monitor leak in tsi148 bridge
Summary
| CVE | CVE-2026-68084 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 12:17:20 UTC |
| Updated | 2026-08-17 05:18:07 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: fix location monitor leak in tsi148 bridge tsi148_probe() allocates a location monitor resource and links it into tsi148_bridge->lm_resources. The probe error path frees this list, but tsi148_remove() only frees the dma, slave and master resource lists, so the location monitor resource is leaked on device unbind or module unload. Free the lm_resources list in tsi148_remove() as well, before tsi148_bridge is freed. |
Risk And Classification
EPSS: 0.001720000 probability, percentile 0.069680000 (date 2026-08-17)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected d22b8ed9a3b0a157b732580258ec16b729265953 18be0ad31b161a8b6fbc90d14355ad40c061b6b0 git | Not specified |
| CNA | Linux | Linux | affected d22b8ed9a3b0a157b732580258ec16b729265953 eef048dd77ebfbf99d7c28f9e9dd331d2af7b6f6 git | Not specified |
| CNA | Linux | Linux | affected d22b8ed9a3b0a157b732580258ec16b729265953 36902ab588ccc2fa07994adf6c5f51cbfe379177 git | Not specified |
| CNA | Linux | Linux | affected d22b8ed9a3b0a157b732580258ec16b729265953 e3ceafa6d8ee6b3a0f7fabe7a551fda909edbd46 git | Not specified |
| CNA | Linux | Linux | affected d22b8ed9a3b0a157b732580258ec16b729265953 c6cda17e98545980e42291fc4282daa8a8ebe384 git | Not specified |
| CNA | Linux | Linux | affected d22b8ed9a3b0a157b732580258ec16b729265953 151edde741f8bc7f2931c5f44ab376d32b0c8beb git | Not specified |
| CNA | Linux | Linux | affected 2.6.32 | Not specified |
| CNA | Linux | Linux | unaffected 2.6.32 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.178 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.145 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.96 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.39 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.4 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/18be0ad31b161a8b6fbc90d14355ad40c061b6b0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/151edde741f8bc7f2931c5f44ab376d32b0c8beb | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/36902ab588ccc2fa07994adf6c5f51cbfe379177 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/eef048dd77ebfbf99d7c28f9e9dd331d2af7b6f6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c6cda17e98545980e42291fc4282daa8a8ebe384 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e3ceafa6d8ee6b3a0f7fabe7a551fda909edbd46 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.