๐Ÿ” CVE Alert

CVE-2026-46288

UNKNOWN 0.0

of: unittest: fix use-after-free in of_unittest_changeset()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: of: unittest: fix use-after-free in of_unittest_changeset() The variable 'parent' is assigned the value of 'nchangeset' earlier in the function, meaning both point to the same struct device_node. The call to of_node_put(nchangeset) can decrement the reference count to zero and free the node if there are no other holders. After that, the code still uses 'parent' to check for the presence of a property and to read a string property, leading to a use-after-free. Fix this by moving the of_node_put() call after the last access to 'parent', avoiding the UAF.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jun 8, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1c668ea65506e67ce2eae07b69bb09fcdd86e309 < 37318d1a27c9cc5a70d3cd7e49e30ec86f2b8ca1 1c668ea65506e67ce2eae07b69bb09fcdd86e309 < 7f0f0926f3010b10cff5e93446258f971e42f2fd 1c668ea65506e67ce2eae07b69bb09fcdd86e309 < 6fdad20b7975bdc32e85b45f8f7c640f6687b81f 1c668ea65506e67ce2eae07b69bb09fcdd86e309 < faecdd423c27f0d6090156a435ba9dbbac0eaddb
Linux / Linux
6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/37318d1a27c9cc5a70d3cd7e49e30ec86f2b8ca1 git.kernel.org: https://git.kernel.org/stable/c/7f0f0926f3010b10cff5e93446258f971e42f2fd git.kernel.org: https://git.kernel.org/stable/c/6fdad20b7975bdc32e85b45f8f7c640f6687b81f git.kernel.org: https://git.kernel.org/stable/c/faecdd423c27f0d6090156a435ba9dbbac0eaddb