CVE-2026-68180: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: intel_th: fix MSC output device reference leak intel_th_output_open() looks up the output device with bus_find_device_by_devt(), which returns the device with a reference that must be dropped after use. commit 95fc36a234da ("intel_th: fix device leak on output open()") attempted to drop the reference from intel_th_output_release(). However, a successful open replaces file->f_op with the output driver file operations before returning, so close runs the output driver release callback instead. For MSC outputs, close runs intel_th_msc_release(), which only removes the per-file iterator and does not drop the device reference taken by intel_th_output_open(). Consequently, every successful MSC output open leaks one device reference. Drop the device reference from intel_th_msc_release(), which is the release path actually used for MSC output files. Remove the now-unused intel_th_output_release() callback from intel_th_output_fops.
Affected products
- Linux Linux: from 5.10.249, before 5.10.265 (fixed in 5.10.265); from 5.15.199, before 5.15.216 (fixed in 5.15.216); from 6.1.162, before 6.1.183 (fixed in 6.1.183); from 6.6.122, before 6.6.148 (fixed in 6.6.148); from 6.12.68, before 6.12.101 (fixed in 6.12.101); from 6.18.8, before 6.18.42 (fixed in 6.18.42); …
Published 2026-08-10. Last modified 2026-08-19.