Junglewise Threat Intelligence

CVE-2026-45941: Linux Kernel locality leak in Infineon I2C TPM driver

CVE-2026-45941 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Infineon TPM driver could allow a local attacker to cause a resource leak. The Trusted Platform Module (TPM) is a hardware component used for secure operations like disk encryption and identity verification. If this component fails to release its 'locality' (a hardware-level access lock), it could lead to system instability or prevent other security processes from accessing the TPM.

Technical details

A vulnerability in the tpm_i2c_infineon driver in the Linux kernel stems from improper error handling in the tpm_tis_i2c_send() function. When get_burstcount() returns an error (such as -EBUSY on timeout), the function returns immediately without releasing the TPM locality acquired at the start of the operation. This results in a locality leak, which can prevent subsequent TPM operations or other system components from correctly interacting with the hardware. The fix introduces a jump to an error label to ensure proper cleanup and locality release.

Affected products

  • Linux Linux Kernel aad628c1d91a

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References