In the Linux kernel, the following vulnerability has been resolved:
iio: temperature: tmp006: use devm_iio_trigger_register
tmp006_probe() allocates the DRDY trigger with devm_iio_trigger_alloc()
but registers it with plain iio_trigger_register(). The driver has no
.remove() callback, so on module unload the trigger stays in the global
trigger list while its memory is freed by devm, leaving a dangling
entry.
Switch to devm_iio_trigger_register() so the registration is undone in
the same devm scope as the allocation.
CVE-2026-64492
NONE
EPSS 0.17%
Updated Jul 25, 2026
Linux
https://git.kernel.org/stable/c/3c5eed894efd93d68d7f6a359a81ddef0e928774
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/a4f8491da9563ba6eb77969ac26fc7052114c476
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/d90f868f56a16e10eedc6552f48d99dff4d275b7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVE Details
CVE ID
CVE-2026-64492
Published Date
Jul 25, 2026
Vendor
Linux
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.17%
Likelihood of exploitation in next 30 days
Percentile:
7.0th percentile (higher than 7.0% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory