CVE-2026-53028
Description
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: Fix error pointer dereference
The variable tps->partner is checked for an error pointer and then if it
is, it sends an error message but does not return and then immediately
dereferenced a few lines below:
tps->partner = typec_register_partner(tps->port, &desc);
if (IS_ERR(tps->partner))
dev_warn(tps->dev, "%s: failed to register partnet\n", __func__);
if (desc.identity) {
typec_partner_set_identity(tps->partner);
cd321x->cur_partner_identity = st.partner_identity;
}
Add early return and fix spelling mistake in error message.
Detected by Smatch:
drivers/usb/typec/tipd/core.c:827 cd321x_update_work() error:
'tps->partner' dereferencing possible ERR_PTR()
Summary dbcve.org
In the Linux kernel USB Type-C driver (drivers/usb/typec/tipd/core.c), the cd321x_update_work() function checks if typec_register_partner() returns an error pointer but fails to return early. The code prints a warning but continues execution, then dereferences tps->partner a few lines later in typec_partner_set_identity() without re-checking, causing a potential kernel NULL/dereference error when the registration fails.
Mitigation
Apply the upstream kernel patch which adds an early return after the error pointer check and corrects the spelling error in the warning message. This is a single-point fix in a kernel driver requiring kernel rebuild and verification.