Activity log
- Created & dismissed (max. allowed matches exceeded) suggestion
intel_th: fix MSC output device reference leak
In the Linux kernel, the following vulnerability has been resolved: intel_th: fix MSC output device reference leak intel_th_output_open() looks up the output device with bus_find_device_by_devt(), which returns the device with a reference that must be dropped after use. commit 95fc36a234da ("intel_th: fix device leak on output open()") attempted to drop the reference from intel_th_output_release(). However, a successful open replaces file->f_op with the output driver file operations before returning, so close runs the output driver release callback instead. For MSC outputs, close runs intel_th_msc_release(), which only removes the per-file iterator and does not drop the device reference taken by intel_th_output_open(). Consequently, every successful MSC output open leaks one device reference. Drop the device reference from intel_th_msc_release(), which is the release path actually used for MSC output files. Remove the now-unused intel_th_output_release() callback from intel_th_output_fops.
References
Affected products
- =<6.6.*
- =<*
- =<7.1.*
- <6.19
- <6.12.101
- ==b71e64ef7ff9443835d1333e3e80ab1e49e5209f
- ==af4b9467296b9a16ebc008147238070236982b6d
- <6.2
- =<6.18.*
- <6.18.42
- <caba30eb8bd321c465ecfc7d850ee85f5b353496
- <761b785a0cfbce43761227bc42a7f984f31f8921
- <5.11
- ==64015cbf06e8bb75b81ae95b997e847b55280f7f
- <5.16
- =<6.12.*
- <c3a28f9cb82425fe0835048ed3677f321e780691
- <ddcf2064d7ec5a8c9afa7cb74442320e443502bc
- ==6.19
- <6.6.148
- <26e27b8dcef1e4df6f30d8f25b3304a506d482b3