CVE-2026-46109
In the Linux kernel, the following vulnerability has been resolved: usb: ulpi: fix memory leak on ulpi_register() error paths Commit 01af542392b5 ("usb: ulpi: fix double free in ulpi_register_interface() error path") removed kfree(ulpi) from ulpi_register_interface() to fix a double-free when device_register() fails. But when ulpi_of_register() or ulpi_read_id() fail before device_register() is called, the ulpi allocation is leaked. Add kfree(ulpi) on both error paths to properly clean up the allocation.
Affected versions
Linux kernel versions
5.10.253,
5.15.203,
6.1.168,
6.6.134,
6.12.81,
6.18.22,
6.19.12,
7.0
and later are affected. Fixed in
5.10.258,
5.15.209,
6.1.175,
6.6.140,
6.12.88,
6.18.30,
7.0.7,
7.1-rc3
and their respective stable series.
References
The following references provide additional information about CVE-2026-46109 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
-
PatchKernel patch commithttps://git.kernel.org/stable/c/0b9fcab1b8608d429e5f239afb197de928d4de7d
-
PatchKernel patch commithttps://git.kernel.org/stable/c/0c2c0c6820fe96fa4be0a0499f8d3f3321b9af6c
-
PatchKernel patch commithttps://git.kernel.org/stable/c/2a71e01b2cf9b4329ff67102c1bea7448c2a2d2d
Frequently asked questions
-
What is CVE-2026-46109?
CVE-2026-46109 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.10.253 onward and has been patched in 5.10.258, 5.15.209, 6.1.175 and others. CVE-2026-46109 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-46109?
Yes — CVE-2026-46109 has been patched. Fixed versions include 5.10.258, 5.15.209, 6.1.175 and others. If you are running Linux kernel 5.10.253 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-46109 actively exploited?
No — CVE-2026-46109 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.