CVE-2026-64492 is a vulnerability in Linux Kernel
Published on July 25, 2026
iio: temperature: tmp006: use devm_iio_trigger_register
In the Linux kernel, the following vulnerability has been resolved:
iio: temperature: tmp006: use devm_iio_trigger_register
tmp006_probe() allocates the DRDY trigger with devm_iio_trigger_alloc()
but registers it with plain iio_trigger_register(). The driver has no
.remove() callback, so on module unload the trigger stays in the global
trigger list while its memory is freed by devm, leaving a dangling
entry.
Switch to devm_iio_trigger_register() so the registration is undone in
the same devm scope as the allocation.
Products Associated with CVE-2026-64492
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 91f75ccf9f032e17cde54f0c01eae2da4f067bc5 and below a4f8491da9563ba6eb77969ac26fc7052114c476 is affected.
- Version 91f75ccf9f032e17cde54f0c01eae2da4f067bc5 and below d90f868f56a16e10eedc6552f48d99dff4d275b7 is affected.
- Version 91f75ccf9f032e17cde54f0c01eae2da4f067bc5 and below 3c5eed894efd93d68d7f6a359a81ddef0e928774 is affected.
- Version 6.13 is affected.
- Before 6.13 is unaffected.
- Version 6.18.39, <= 6.18.* is unaffected.
- Version 7.1.4, <= 7.1.* is unaffected.
- Version 7.2-rc1, <= * is unaffected.