CVE-2026-46109

In the Linux kernel, the following vulnerability has been resolved: usb: ulpi: fix memory leak on ulpi_register() error paths Commit 01af542392b5 ("usb: ulpi: fix double free in ulpi_register_interface() error path") removed kfree(ulpi) from ulpi_register_interface() to fix a double-free when device_register() fails. But when ulpi_of_register() or ulpi_read_id() fail before device_register() is called, the ulpi allocation is leaked. Add kfree(ulpi) on both error paths to properly clean up the allocation.

Package Linux Kernel
Published 2026-05-28
Last modified 2026-06-01
Patch available
Yes

Affected versions

Linux kernel versions 5.10.253, 5.15.203, 6.1.168, 6.6.134, 6.12.81, 6.18.22, 6.19.12, 7.0 and later are affected. Fixed in 5.10.258, 5.15.209, 6.1.175, 6.6.140, 6.12.88, 6.18.30, 7.0.7, 7.1-rc3 and their respective stable series.

Affected from
≥ 5.10.253 ≥ 5.15.203 ≥ 6.1.168 ≥ 6.6.134 ≥ 6.12.81 ≥ 6.18.22 ≥ 6.19.12 ≥ 7.0
Fixed in
✓ 5.10.258 5.10.x ✓ 5.15.209 5.15.x ✓ 6.1.175 6.1.x ✓ 6.6.140 6.6.x ✓ 6.12.88 6.12.x ✓ 6.18.30 6.18.x ✓ 7.0.7 7.0.x ✓ 7.1-rc3

References

The following references provide additional information about CVE-2026-46109 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.

Frequently asked questions

  • What is CVE-2026-46109?

    CVE-2026-46109 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.10.253 onward and has been patched in 5.10.258, 5.15.209, 6.1.175 and others. CVE-2026-46109 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-46109?

    Yes — CVE-2026-46109 has been patched. Fixed versions include 5.10.258, 5.15.209, 6.1.175 and others. If you are running Linux kernel 5.10.253 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-46109 actively exploited?

    No — CVE-2026-46109 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.