In the Linux kernel, the following vulnerability has been resolved: intel_th: fix MSC output...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
intel_th: fix MSC output device reference leak
intel_th_output_open() looks up the output device with bus_find_device_by_devt(), which returns the device with a reference that must be dropped after use.
commit 95fc36a234da ("intel_th: fix device leak on output open()") attempted to drop the reference from intel_th_output_release(). However, a successful open replaces file->f_op with the output driver file operations before returning, so close runs the output driver release callback instead.
For MSC outputs, close runs intel_th_msc_release(), which only removes the per-file iterator and does not drop the device reference taken by intel_th_output_open(). Consequently, every successful MSC output open leaks one device reference.
Drop the device reference from intel_th_msc_release(), which is the release path actually used for MSC output files. Remove the now-unused intel_th_output_release() callback from intel_th_output_fops.
🔗 References (10)
- https://nvd.nist.gov/vuln/detail/CVE-2026-68180
- https://git.kernel.org/stable/c/26e27b8dcef1e4df6f30d8f25b3304a506d482b3
- https://git.kernel.org/stable/c/761b785a0cfbce43761227bc42a7f984f31f8921
- https://git.kernel.org/stable/c/c3a28f9cb82425fe0835048ed3677f321e780691
- https://git.kernel.org/stable/c/caba30eb8bd321c465ecfc7d850ee85f5b353496
- https://git.kernel.org/stable/c/ddcf2064d7ec5a8c9afa7cb74442320e443502bc
- https://git.kernel.org/stable/c/12ad4fad748e6e563ff4480f03b89134a41b5c37
- https://git.kernel.org/stable/c/141641a70ed337e54487f766ede745fc2ce44c42
- https://git.kernel.org/stable/c/df55842fddbcdb80e6dd16680439c0f780ed592e
- https://github.com/advisories/GHSA-qq33-46pr-rg4r