staging: vme_user: fix location monitor leak in tsi148 bridge

Summary

CVECVE-2026-68084
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-10 12:17:20 UTC
Updated2026-08-10 12:17:20 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: staging: vme_user: fix location monitor leak in tsi148 bridge tsi148_probe() allocates a location monitor resource and links it into tsi148_bridge->lm_resources. The probe error path frees this list, but tsi148_remove() only frees the dma, slave and master resource lists, so the location monitor resource is leaked on device unbind or module unload. Free the lm_resources list in tsi148_remove() as well, before tsi148_bridge is freed.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected d22b8ed9a3b0a157b732580258ec16b729265953 18be0ad31b161a8b6fbc90d14355ad40c061b6b0 git Not specified
CNA Linux Linux affected d22b8ed9a3b0a157b732580258ec16b729265953 eef048dd77ebfbf99d7c28f9e9dd331d2af7b6f6 git Not specified
CNA Linux Linux affected d22b8ed9a3b0a157b732580258ec16b729265953 36902ab588ccc2fa07994adf6c5f51cbfe379177 git Not specified
CNA Linux Linux affected d22b8ed9a3b0a157b732580258ec16b729265953 e3ceafa6d8ee6b3a0f7fabe7a551fda909edbd46 git Not specified
CNA Linux Linux affected d22b8ed9a3b0a157b732580258ec16b729265953 c6cda17e98545980e42291fc4282daa8a8ebe384 git Not specified
CNA Linux Linux affected d22b8ed9a3b0a157b732580258ec16b729265953 151edde741f8bc7f2931c5f44ab376d32b0c8beb git Not specified
CNA Linux Linux affected 2.6.32 Not specified
CNA Linux Linux unaffected 2.6.32 semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.96 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.39 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.4 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc3 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/18be0ad31b161a8b6fbc90d14355ad40c061b6b0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/151edde741f8bc7f2931c5f44ab376d32b0c8beb 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/36902ab588ccc2fa07994adf6c5f51cbfe379177 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/eef048dd77ebfbf99d7c28f9e9dd331d2af7b6f6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c6cda17e98545980e42291fc4282daa8a8ebe384 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e3ceafa6d8ee6b3a0f7fabe7a551fda909edbd46 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report