MEDIUM

CVE-2026-53028

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: Fix error pointer dereference

The variable tps->partner is checked for an error pointer and then if it
is, it sends an error message but does not return and then immediately
dereferenced a few lines below:

tps->partner = typec_register_partner(tps->port, &desc);
if (IS_ERR(tps->partner))
dev_warn(tps->dev, "%s: failed to register partnet\n", __func__);

if (desc.identity) {
typec_partner_set_identity(tps->partner);
cd321x->cur_partner_identity = st.partner_identity;
}

Add early return and fix spelling mistake in error message.

Detected by Smatch:
drivers/usb/typec/tipd/core.c:827 cd321x_update_work() error:
'tps->partner' dereferencing possible ERR_PTR()

Summary dbcve.org

In the Linux kernel USB Type-C driver (drivers/usb/typec/tipd/core.c), the cd321x_update_work() function checks if typec_register_partner() returns an error pointer but fails to return early. The code prints a warning but continues execution, then dereferences tps->partner a few lines later in typec_partner_set_identity() without re-checking, causing a potential kernel NULL/dereference error when the registration fails.

Mitigation

Apply the upstream kernel patch which adds an early return after the error pointer check and corrects the spelling error in the warning message. This is a single-point fix in a kernel driver requiring kernel rebuild and verification.

Patch Commit

Weakness (CWE)

CWE-476 NULL Pointer Dereference

EPSS Score

0.12%
Probability of exploitation in next 30 days
2.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE