Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-46109

CVE-2026-46109: Linux Kernel ULPI Memory Leak Vulnerability

CVE-2026-46109 is a memory leak vulnerability in the Linux kernel ULPI subsystem that occurs on ulpi_register() error paths. This post covers the technical details, affected versions, security impact, and mitigation.

Published:

CVE-2026-46109 Overview

CVE-2026-46109 is a memory leak vulnerability in the Linux kernel's USB ULPI (UTMI+ Low Pin Interface) subsystem. The flaw exists in the ulpi_register() function, where the ulpi allocation is leaked when ulpi_of_register() or ulpi_read_id() fail before device_register() is called. The defect was introduced by an earlier fix (commit 01af542392b5) that removed kfree(ulpi) from ulpi_register_interface() to address a double-free condition. The maintainers resolved the issue by adding kfree(ulpi) on both error paths to properly clean up the allocation.

Critical Impact

Repeated triggering of the ULPI registration error path causes kernel memory exhaustion, leading to system instability or denial of service on affected Linux systems.

Affected Products

  • Linux kernel (multiple stable branches receiving the backport)
  • Systems using USB ULPI PHY drivers
  • Embedded and SoC platforms relying on ULPI USB transceivers

Discovery Timeline

  • 2026-05-28 - CVE-2026-46109 published to NVD
  • 2026-05-28 - Last updated in NVD database

Technical Details for CVE-2026-46109

Vulnerability Analysis

The vulnerability is a memory leak [CWE-401] in the Linux kernel USB ULPI subsystem. The ulpi_register() function allocates a struct ulpi early in its execution before performing several initialization steps. A prior patch removed the explicit kfree(ulpi) call from ulpi_register_interface() because device_register() failures invoked put_device(), which would free the allocation through the device release callback. That fix correctly resolved a double-free condition.

However, the cleanup logic did not account for failure paths preceding device_register(). When ulpi_of_register() or ulpi_read_id() returns an error, the function exits without registering the device. Because device_register() was never called, the release callback never runs, and the ulpi allocation remains orphaned in kernel memory. Each failed registration attempt leaks a small but non-trivial structure.

Root Cause

The root cause is incomplete error-path cleanup following the prior double-free remediation. The kernel relied on the device subsystem to free the allocation through put_device(), but this mechanism only applies after device_register() has been invoked. Errors arising from ulpi_of_register() or ulpi_read_id() occur earlier in the function, leaving the allocation without an owner responsible for releasing it.

Attack Vector

Triggering the leak requires conditions that cause ulpi_of_register() or ulpi_read_id() to fail. These functions can fail due to malformed device tree entries, hardware communication errors, or unsupported ULPI PHY identifiers. On systems where the failure condition can be repeatedly induced, kernel memory exhaustion becomes feasible over time. The fix adds kfree(ulpi) on both error paths to ensure proper cleanup. See the upstream patches for details: Git Kernel Patch 0b9fcab, Git Kernel Patch 2a71e01, Git Kernel Patch b0c0d44, Git Kernel Patch be2c1d8, and Git Kernel Patch f30ccfc.

Detection Methods for CVE-2026-46109

Indicators of Compromise

  • Gradual increase in unaccounted kernel slab memory consumption on systems with ULPI USB controllers
  • Repeated kernel log messages indicating ulpi_read_id or ulpi_of_register failures
  • Long-running systems experiencing memory pressure without identifiable userspace cause

Detection Strategies

  • Compare running kernel version against patched stable releases referenced in the upstream commits
  • Audit boot-time and runtime kernel logs (dmesg) for ULPI registration failure messages
  • Use slabtop and /proc/slabinfo to monitor anomalous growth of generic kernel allocations on ULPI-equipped hardware

Monitoring Recommendations

  • Track kernel memory utilization trends across endpoints and embedded devices over extended uptime windows
  • Alert on recurring ULPI subsystem error messages that indicate the vulnerable code path is being exercised
  • Inventory kernel versions across Linux assets to confirm patch coverage on USB-attached and SoC platforms

How to Mitigate CVE-2026-46109

Immediate Actions Required

  • Update to a Linux kernel version that includes one of the upstream fix commits (0b9fcab, 2a71e01, b0c0d44, be2c1d8, or f30ccfc)
  • Apply distribution-provided kernel updates as they become available for affected stable branches
  • Reboot systems after kernel updates to ensure the patched code is loaded

Patch Information

The fix adds kfree(ulpi) on both error paths in ulpi_register() to clean up the allocation when ulpi_of_register() or ulpi_read_id() fail. Patches are available across multiple Linux stable branches via the kernel.org commits listed in the technical references above.

Workarounds

  • Ensure device tree entries and ULPI PHY hardware are correctly configured to minimize occurrences of ulpi_of_register() and ulpi_read_id() failures
  • Reboot affected systems periodically if patching is not immediately possible and leak symptoms are observed
  • Restrict physical access to hardware that could be manipulated to repeatedly trigger ULPI registration failures
bash
# Verify the running kernel version and check for the fix
uname -r

# On Debian/Ubuntu, update the kernel package
sudo apt update && sudo apt install --only-upgrade linux-image-generic

# On RHEL/Fedora, update the kernel package
sudo dnf update kernel

# Reboot to load the patched kernel
sudo systemctl reboot

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.