CVE-2026-64463

critical

Description

In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres rt1711h_probe() registers the TCPCI port before requesting the interrupt and enabling alert interrupts. If either of those later steps fails, the probe function returns without unregistering the TCPCI port. The explicit unregister currently only happens from the remove callback. Register a devres action immediately after tcpci_register_port() succeeds, so tcpci_unregister_port() runs on later probe failures and on driver detach. Drop the remove callback to avoid unregistering the same port twice. This issue was identified during our ongoing static-analysis research while reviewing kernel code.

References

https://git.kernel.org/stable/c/e8da46d99d3710106e7c44db14566bf9b57386b5

https://git.kernel.org/stable/c/e5406c8fb71cd2f89a46300a746f6e7972e621e8

https://git.kernel.org/stable/c/ce2e36e8759dfbfe546723810c306f42f484866d

https://git.kernel.org/stable/c/94b1abf1af94aa5a355e9f03675e07bccfc41c4b

https://git.kernel.org/stable/c/569f18a83eed0b0be4615f0c7bed40fb5c50e2e6

Details

Source: Mitre, NVD

Published: 2026-07-25

Updated: 2026-07-25

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00209