CVE-2026-23091
In the Linux kernel, the following vulnerability has been resolved: intel_th: fix device leak on output open() Make sure to drop the reference taken when looking up the th device during output device open() on errors and on close().
Does this matter?
Lower severity and a low EPSS score (0.13%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: intel_th: fix device leak on output open() Make sure to drop the reference taken when looking up the th device during output device open() on errors and on close(). Note that a recent commit fixed the leak in a couple of open() error paths but not all of them, and the reference is still leaking on successful open().
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.13% probability · 3th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0fca16c5591534cc1fec8b6181277ee3a3d0f26cPatch
- https://git.kernel.org/stable/c/64015cbf06e8bb75b81ae95b997e847b55280f7fPatch
- https://git.kernel.org/stable/c/95fc36a234da24bbc5f476f8104a5a15f99ed3e3Patch
- https://git.kernel.org/stable/c/af4b9467296b9a16ebc008147238070236982b6dPatch
- https://git.kernel.org/stable/c/b71e64ef7ff9443835d1333e3e80ab1e49e5209fPatch
- https://git.kernel.org/stable/c/bf7785434b5d05d940d936b78925080950bd54ddPatch
- https://git.kernel.org/stable/c/f9b059bda4276f2bb72cb98ec7875a747f042ea2Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.