Junglewise Threat Intelligence

CVE-2026-46109: Linux kernel memory leak in USB ULPI registration

CVE-2026-46109 · Severity: info · CVSS 0 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak vulnerability was identified in the Linux kernel's USB ULPI interface driver. This issue occurs when certain hardware registration steps fail, causing the system to retain memory that should have been released. While primarily a stability concern, repeated occurrences could eventually lead to system resource exhaustion.

Technical details

A memory leak exists in drivers/usb/common/ulpi.c within the ulpi_register() function. A previous fix for a double-free vulnerability (commit 01af542392b5) removed a kfree() call that was necessary for error paths occurring before device_register() is invoked. Specifically, if ulpi_of_register() or ulpi_read_id() fail, the allocated 'ulpi' structure is never freed. An attacker or a malfunctioning hardware device could trigger these error paths to leak kernel memory. The issue has been resolved by adding explicit kfree(ulpi) calls to the affected error handling blocks.

Affected products

  • Linux Linux kernel All versions prior to the May 2026 patches

Timeline

  • 2026-04-07: other: Patch submitted by developer
  • 2026-05-28: advisory: CVE-2026-46109 published by NVD

References