CVE-2026-46109: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: usb: ulpi: fix memory leak on ulpi_register() error paths Commit 01af542392b5 ("usb: ulpi: fix double free in ulpi_register_interface() error path") removed kfree(ulpi) from ulpi_register_interface() to fix a double-free when device_register() fails. But when ulpi_of_register() or ulpi_read_id() fail before device_register() is called, the ulpi allocation is leaked. Add kfree(ulpi) on both error paths to properly clean up the allocation.

Affected products

  • Linux Linux Kernel: from 5.10.253, before 5.10.258 (fixed in 5.10.258); from 5.15.203, before 5.15.209 (fixed in 5.15.209); from 6.1.168, before 6.1.175 (fixed in 6.1.175); from 6.6.134, before 6.6.140 (fixed in 6.6.140); from 6.12.81, before 6.12.88 (fixed in 6.12.88); from 6.18.22, before 6.18.30 (fixed in 6.18.30); …

Published 2026-05-28. Last modified 2026-06-24.