In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure get_burstcount() can return -EBUSY on timeout. When this happens, the function returns directly without releasing the locality that was acquired at the beginning of tpm_tis_i2c_send(). Use goto out_err to ensure proper cleanup when get_burstcount() fails.
Update Linux/Linux to 8f124c5582d443ac9fb690db26d08cab5d6ba76e if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scantpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure affects Linux/Linux (generic), Linux/Linux (generic). Severity is medium. In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure get_burstcount() can return -EBUSY on timeout. When this happens, the function returns directly without releasing the locality that was acquired at the beginning of tpm_tis_i2c_send(). Use goto out_err to ensure proper cleanup when get_burstcount() fails.
AI coding agents often install or upgrade packages automatically in generic. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <8f124c5582d443ac9fb690db26d08cab5d6ba76e || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <c24c9c4cab11858f22f309521ba7ea5b1e7385f2 || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <1bb8f8826d0748b4b92a98fb6b6dfe52081739f5 || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <948966e546f29af04391d98b8e378e4a7670c1c1 || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <a61b8412e3eb8b71646dba867e8252d8560a1a27 || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <1a22048c1117cdfac185ba450aba67ed6b65dc87 || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <2f7a665e1323359d99c74301d1e180f5e2c40181 || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <bbd6e97c836cbeb9606d7b7e5dcf8a1d89525713 |
In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure get_burstcount() can return -EBUSY on timeout. When this happens, the function returns directly without releasing the locality that was acquired at the beginning of tpm_tis_i2c_send(). Use goto out_err to ensure proper cleanup when get_burstcount() fails.
Update Linux/Linux to 8f124c5582d443ac9fb690db26d08cab5d6ba76e if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scantpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure affects Linux/Linux (generic), Linux/Linux (generic). Severity is medium. In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure get_burstcount() can return -EBUSY on timeout. When this happens, the function returns directly without releasing the locality that was acquired at the beginning of tpm_tis_i2c_send(). Use goto out_err to ensure proper cleanup when get_burstcount() fails.
AI coding agents often install or upgrade packages automatically in generic. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <8f124c5582d443ac9fb690db26d08cab5d6ba76e || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <c24c9c4cab11858f22f309521ba7ea5b1e7385f2 || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <1bb8f8826d0748b4b92a98fb6b6dfe52081739f5 || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <948966e546f29af04391d98b8e378e4a7670c1c1 || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <a61b8412e3eb8b71646dba867e8252d8560a1a27 || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <1a22048c1117cdfac185ba450aba67ed6b65dc87 || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <2f7a665e1323359d99c74301d1e180f5e2c40181 || >=aad628c1d91a6db57e572e4c1f35e863d81061d7 <bbd6e97c836cbeb9606d7b7e5dcf8a1d89525713 |
| 8f124c5582d443ac9fb690db26d08cab5d6ba76e, c24c9c4cab11858f22f309521ba7ea5b1e7385f2, 1bb8f8826d0748b4b92a98fb6b6dfe52081739f5, 948966e546f29af04391d98b8e378e4a7670c1c1, a61b8412e3eb8b71646dba867e8252d8560a1a27, 1a22048c1117cdfac185ba450aba67ed6b65dc87, 2f7a665e1323359d99c74301d1e180f5e2c40181, bbd6e97c836cbeb9606d7b7e5dcf8a1d89525713 |
| Linux/Linuxgeneric | 3.7 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 8f124c5582d443ac9fb690db26d08cab5d6ba76e, c24c9c4cab11858f22f309521ba7ea5b1e7385f2, 1bb8f8826d0748b4b92a98fb6b6dfe52081739f5, 948966e546f29af04391d98b8e378e4a7670c1c1, a61b8412e3eb8b71646dba867e8252d8560a1a27, 1a22048c1117cdfac185ba450aba67ed6b65dc87, 2f7a665e1323359d99c74301d1e180f5e2c40181, bbd6e97c836cbeb9606d7b7e5dcf8a1d89525713 |
| Linux/Linuxgeneric | 3.7 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard