CVE-2026-68084

Unknown

Last modified

CVE-2026-68084 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: fix location monitor leak in tsi148 bridge tsi148_probe() allocates a location monitor resource and links it into tsi148_bridge->lm_resources. The probe error path frees this list, but tsi148_remove() only frees the dma, slave and master resource lists, so the location monitor resource is leaked on device unbind or module unload. Free the lm_resources list in tsi148_remove() as well, before tsi148_bridge is freed..

Description

In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: fix location monitor leak in tsi148 bridge tsi148_probe() allocates a location monitor resource and links it into tsi148_bridge->lm_resources. The probe error path frees this list, but tsi148_remove() only frees the dma, slave and master resource lists, so the location monitor resource is leaked on device unbind or module unload. Free the lm_resources list in tsi148_remove() as well, before tsi148_bridge is freed.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= d22b8ed9a3b0a157b732580258ec16b729265953, < 18be0ad31b161a8b6fbc90d14355ad40c061b6b0; >= d22b8ed9a3b0a157b732580258ec16b729265953, < eef048dd77ebfbf99d7c28f9e9dd331d2af7b6f6; >= d22b8ed9a3b0a157b732580258ec16b729265953, < 36902ab588ccc2fa07994adf6c5f51cbfe379177; >= d22b8ed9a3b0a157b732580258ec16b729265953, < e3ceafa6d8ee6b3a0f7fabe7a551fda909edbd46; >= d22b8ed9a3b0a157b732580258ec16b729265953, < c6cda17e98545980e42291fc4282daa8a8ebe384; >= d22b8ed9a3b0a157b732580258ec16b729265953, < 151edde741f8bc7f2931c5f44ab376d32b0c8beb
LinuxLinux2.6.32

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68084?
In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: fix location monitor leak in tsi148 bridge tsi148_probe() allocates a location monitor resource and links it into tsi148_bridge->lm_resources. The probe error path frees this list, but tsi148_remove() only frees the dma, slave and master resource lists, so the location monitor resource is leaked on device unbind or module unload. Free the lm_resources list in tsi148_remove() as well, before tsi148_bridge is freed.
How severe is CVE-2026-68084?
Severity scoring for CVE-2026-68084 is pending analysis.
How do I fix CVE-2026-68084?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68084?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST