Back to overview

CVE-2026-64492

Description
In the Linux kernel, the following vulnerability has been resolved: iio: temperature: tmp006: use devm_iio_trigger_register tmp006_probe() allocates the DRDY trigger with devm_iio_trigger_alloc() but registers it with plain iio_trigger_register(). The driver has no .remove() callback, so on module unload the trigger stays in the global trigger list while its memory is freed by devm, leaving a dangling entry. Switch to devm_iio_trigger_register() so the registration is undone in the same devm scope as the allocation.

Metadata

CVE ID
CVE-2026-64492
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 15:36 UTC
Published
2026-07-25 08:51 UTC
Last updated
2026-07-25 08:51 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 91f75ccf9f032e17cde54f0c01eae2da4f067bc5 < a4f8491da9563ba6eb77969ac26fc7052114c476, 91f75ccf9f032e17cde54f0c01eae2da4f067bc5 < d90f868f56a16e10eedc6552f48d99dff4d275b7, 91f75ccf9f032e17cde54f0c01eae2da4f067bc5 < 3c5eed894efd93d68d7f6a359a81ddef0e928774
Linux Linux 6.13, 0 < 6.13, 6.18.39 ≤ 6.18.*, 7.1.4 ≤ 7.1.* …
Back to overview