CVE-2026-68180 PUBLISHED

intel_th: fix MSC output device reference leak

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

intel_th: fix MSC output device reference leak

intel_th_output_open() looks up the output device with bus_find_device_by_devt(), which returns the device with a reference that must be dropped after use.

commit 95fc36a234da ("intel_th: fix device leak on output open()") attempted to drop the reference from intel_th_output_release(). However, a successful open replaces file->f_op with the output driver file operations before returning, so close runs the output driver release callback instead.

For MSC outputs, close runs intel_th_msc_release(), which only removes the per-file iterator and does not drop the device reference taken by intel_th_output_open(). Consequently, every successful MSC output open leaks one device reference.

Drop the device reference from intel_th_msc_release(), which is the release path actually used for MSC output files. Remove the now-unused intel_th_output_release() callback from intel_th_output_fops.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from bf7785434b5d05d940d936b78925080950bd54dd to ddcf2064d7ec5a8c9afa7cb74442320e443502bc (excl.)
  • affected from 0fca16c5591534cc1fec8b6181277ee3a3d0f26c to 26e27b8dcef1e4df6f30d8f25b3304a506d482b3 (excl.)
  • affected from f9b059bda4276f2bb72cb98ec7875a747f042ea2 to caba30eb8bd321c465ecfc7d850ee85f5b353496 (excl.)
  • affected from 95fc36a234da24bbc5f476f8104a5a15f99ed3e3 to c3a28f9cb82425fe0835048ed3677f321e780691 (excl.)
  • affected from 95fc36a234da24bbc5f476f8104a5a15f99ed3e3 to 761b785a0cfbce43761227bc42a7f984f31f8921 (excl.)
  • Version af4b9467296b9a16ebc008147238070236982b6d is affected
  • Version 64015cbf06e8bb75b81ae95b997e847b55280f7f is affected
  • Version b71e64ef7ff9443835d1333e3e80ab1e49e5209f is affected
  • affected from 6.6.122 to 6.6.148 (excl.)
  • affected from 6.12.68 to 6.12.101 (excl.)
  • affected from 6.18.8 to 6.18.42 (excl.)
  • affected from 5.10.249 to 5.11 (excl.)
  • affected from 5.15.199 to 5.16 (excl.)
  • affected from 6.1.162 to 6.2 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.19 is affected
  • unaffected from 0 to 6.19 (excl.)
  • unaffected from 6.6.148 to 6.6.* (incl.)
  • unaffected from 6.12.101 to 6.12.* (incl.)
  • unaffected from 6.18.42 to 6.18.* (incl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc5 to * (incl.)

References