CVE-2026-64463
Description
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres rt1711h_probe() registers the TCPCI port before requesting the interrupt and enabling alert interrupts. If either of those later steps fails, the probe function returns without unregistering the TCPCI port. The explicit unregister currently only happens from the remove callback. Register a devres action immediately after tcpci_register_port() succeeds, so tcpci_unregister_port() runs on later probe failures and on driver detach. Drop the remove callback to avoid unregistering the same port twice. This issue was identified during our ongoing static-analysis research while reviewing kernel code.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/ce2e36e8759dfbfe546723810c306f42f484866d
- https://git.kernel.org/stable/c/94b1abf1af94aa5a355e9f03675e07bccfc41c4b
- https://git.kernel.org/stable/c/e5406c8fb71cd2f89a46300a746f6e7972e621e8
- https://git.kernel.org/stable/c/569f18a83eed0b0be4615f0c7bed40fb5c50e2e6
- https://git.kernel.org/stable/c/e8da46d99d3710106e7c44db14566bf9b57386b5
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.