Bug 2482007 (CVE-2026-46096) - CVE-2026-46096 kernel: tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public()
Summary: CVE-2026-46096 kernel: tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_r...
Keywords:
Status: NEW
Alias: CVE-2026-46096
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
unspecified
unspecified
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-27 15:06 UTC by OSIDB Bzimport
Modified: 2026-05-27 16:52 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-27 15:06:45 UTC
In the Linux kernel, the following vulnerability has been resolved:

tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public()

tpm2_read_public() calls tpm_buf_init() but fails to call
tpm_buf_destroy() on two exit paths, leaking a page allocation:

1. When name_size() returns an error (unrecognized hash algorithm),
   the function returns directly without destroying the buffer.

2. On the success path, the buffer is never destroyed before
   returning.

All other error paths in the function correctly call
tpm_buf_destroy() before returning.

Fix both by adding the missing tpm_buf_destroy() calls.


Note You need to log in before you can comment on or make changes to this bug.