GHSA-rcq8-h22x-4p97unknown

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Release request...

Published
September 24, 2026
Last Modified
October 3, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response()

If tb_cfg_request() fails setting up the request (for example the control channel is shut down already) it returns an error without calling the callback. To avoid leaking that memory, call tb_cfg_request_put() if tb_cfg_request() fails.

🔗 References (9)