CVE-2026-45941
In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure get_burstcount() can return -EBUSY on timeout. When this happens, the function returns directly without releasing the locality that was acquired at the beginning of tpm_tis_i2c_send(). Use goto out_err to ensure proper cleanup when get_burstcount() fails.
- Published May 27, 2026
- CVSS 5.5 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available