CVE-2026-43375 PUBLISHED

net: mctp: fix device leak on probe failure

Assigner: Linux
Reserved: 01.05.2026 Published: 08.05.2026 Updated: 08.05.2026

In the Linux kernel, the following vulnerability has been resolved:

net: mctp: fix device leak on probe failure

Driver core holds a reference to the USB interface and its parent USB device while the interface is bound to a driver and there is no need to take additional references unless the structures are needed after disconnect.

This driver takes a reference to the USB device during probe but does not to release it on probe failures.

Drop the redundant device reference to fix the leak, reduce cargo culting, make it easier to spot drivers where an extra reference is needed, and reduce the risk of further memory leaks.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 0791c0327a6e4e7691d6fc5ad334c215de04dcc9 to 3224990fb16a831aabc50b67c74f5d0074ce80dd (excl.)
  • affected from 0791c0327a6e4e7691d6fc5ad334c215de04dcc9 to ec9538f9b5cd1db5e8c612aa636b6119b6355c5d (excl.)
  • affected from 0791c0327a6e4e7691d6fc5ad334c215de04dcc9 to 224a0d284c3caf1951302d1744a714784febed71 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.15 is affected
  • unaffected from 0 to 6.15 (excl.)
  • unaffected from 6.18.19 to 6.18.* (incl.)
  • unaffected from 6.19.9 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References