Unchecked Return Value in Linux kernel - CVE-2026-90070
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause TPM status checks to complete spuriously.
The vulnerability exists due to an unchecked return value in the st33zp24_status callback when processing failed TPM transport reads. A local user can trigger a TPM status read to cause TPM status checks to complete spuriously.
On I2C transports, this can occur when the register-select write is short or fails.
Affected software
How to mitigate CVE-2026-90070
External References
- https://git.kernel.org/stable/c/14feaa498c20c1b7ddefe27de5329aaff822cc0d
- https://git.kernel.org/stable/c/1bfd5c54e40704ce93d128a25de3d8dd772bf183
- https://git.kernel.org/stable/c/38c26fe4522963a91d4fb02c844d8faa740fe9d1
- https://git.kernel.org/stable/c/4973e8386257eed10e5433a94a53bcc6ec37d2a1
- https://git.kernel.org/stable/c/8b92687708f5ef980de01c2042dbd76d11f78547
- https://git.kernel.org/stable/c/981307e2e8a930da492c2bcf763865c47c2a5165
- https://git.kernel.org/stable/c/d732cfc4befe28f02ec82ed5fd2bc2a21fbabd42
- https://git.kernel.org/stable/c/e6d7d9b665419cda3e9f91030d81c9f8ba71e51d