CVE-2026-23091

Source
https://cve.org/CVERecord?id=CVE-2026-23091
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23091.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23091
Downstream
Related
Published
2026-02-04T16:08:14.295Z
Modified
2026-03-24T08:59:18.902523Z
Summary
intel_th: fix device leak on output open()
Details

In the Linux kernel, the following vulnerability has been resolved:

intel_th: fix device leak on output open()

Make sure to drop the reference taken when looking up the th device during output device open() on errors and on close().

Note that a recent commit fixed the leak in a couple of open() error paths but not all of them, and the reference is still leaking on successful open().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23091.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
39f4034693b7c7bd1fe4cb58c93259d600f55561
Fixed
af4b9467296b9a16ebc008147238070236982b6d
Fixed
64015cbf06e8bb75b81ae95b997e847b55280f7f
Fixed
b71e64ef7ff9443835d1333e3e80ab1e49e5209f
Fixed
bf7785434b5d05d940d936b78925080950bd54dd
Fixed
0fca16c5591534cc1fec8b6181277ee3a3d0f26c
Fixed
f9b059bda4276f2bb72cb98ec7875a747f042ea2
Fixed
95fc36a234da24bbc5f476f8104a5a15f99ed3e3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23091.json"