Executive brief
A vulnerability was identified in the Linux kernel's USB Type-C driver for Richtek RT1711H controllers. Under specific hardware initialization failure conditions, the system may fail to properly clean up resources, potentially leading to unstable system behavior or resource leaks. This affects devices using this specific USB controller, though it typically requires local access to exploit.
Technical details
A resource management issue exists in drivers/usb/typec/tcpm/tcpci_rt1711h.c within the rt1711h_probe() function. The driver registers a TCPCI port but does not unregister it if later calls, such as requesting threaded interrupts or enabling alert interrupts, fail. This results in a dangling registration because the unregister logic was previously only present in the driver's remove callback. The fix implements devres (device resource management) via devm_add_action_or_reset to ensure the port is automatically unregistered upon probe failure or driver detachment. An attacker with local access might trigger this condition to cause resource exhaustion or kernel instability.
Affected products
- Linux Linux Kernel 4.19.131 to 4.20, 5.4.50 to 5.5, 5.7.7 to 5.8, and later versions prior to 6.6.145/6.12.96
Timeline
- 2026-07-06: other: Patch submitted by maintainers
- 2026-07-25: advisory: CVE-2026-64463 published
References
- https://git.kernel.org/stable/c/569f18a83eed0b0be4615f0c7bed40fb5c50e2e6
- https://git.kernel.org/stable/c/94b1abf1af94aa5a355e9f03675e07bccfc41c4b
- https://git.kernel.org/stable/c/ce2e36e8759dfbfe546723810c306f42f484866d
- https://git.kernel.org/stable/c/e5406c8fb71cd2f89a46300a746f6e7972e621e8
- https://git.kernel.org/stable/c/e8da46d99d3710106e7c44db14566bf9b57386b5