Executive brief
A vulnerability was identified in the Linux kernel's driver for the Texas Instruments FPC202 dual-port controller. The issue involves a memory leak that occurs when the system attempts to initialize the hardware. If exploited, this could allow a local user to gradually exhaust system memory, potentially leading to a system crash or reduced performance.
Technical details
A memory leak vulnerability (CWE-401) exists in the drivers/misc/ti_fpc202.c component of the Linux kernel. The fpc202_probe function fails to properly release device node references during its iteration over child nodes. An attacker with local access could trigger this leak to exhaust kernel memory, leading to a denial of service. The fix replaces the manual iteration with the for_each_child_of_node_scoped() macro, which ensures that device node references are automatically released when the loop scope ends. Patches have been released for multiple stable kernel branches including 6.18.x and 6.19.x.
Affected products
- Linux Linux Kernel 6.16 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2025-12-26: other: Patch authored
- 2026-05-06: disclosed: CVE published
- 2026-05-13: advisory: NVD analysis completed