CVE-2026-89744
device property: fix infinite loop in fwnode_for_each_child_node()
In the Linux kernel, the following vulnerability has been resolved: device property: fix infinite loop in fwnode_for_each_child_node() When iterate over children of a fwnode that has a secondary fwnode, fwnode_get_next_child_node() can enter an infinite loop if the secondary fwnode has more than one child. Parent Child (Primary fwnode) FWa: {FWa1, FWa2, FWa3} (Secondary fwnode) FWb: {FWb1, FWb2} In this case: โโ> fwnode_get_next_child_node(FWa, FWa1) โ - fwnode_call_ptr_op(FWa, get_next_child_node, FWa1) returns FWa2 โ โ ... โ โ fwnode_get_next_child_node(FWa, FWa3) โ - fwnode_call_ptr_op(FWa, get_next_child_node, FWa3) returns NULL โ - fwnode_call_ptr_op(FWb, get_next_child_node, FWa3) returns FWb1 โ โ fwnode_get_next_child_node(FWa, FWb1) โ - fwnode_call_ptr_op(FWa, get_next_child_node, FWb1) returns FWa1 โโโโโโ This cause fwnode_for_each_child_node() to loop indefinitely, reapeatedly output {FWa1, FWa2, FWa3, FWb1, FWa1, ...}. The root cause is that when the current child (FWb1) belongs to the secondary fwnode, calling get_next_child_node() on the parimary fwnode incorrectly returns the first child (FWa1) again instead of NULL. Fix this by dynamically checking the parent fwnode of the current child before calling get_next_child_node(). This approach follows the pattern established in commit b5b41ab6b0c1 ("device property: Check fwnode->secondary in fwnode_graph_get_next_endpoint()").
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | Sep 11, 2026 |
| Last Updated | Sep 14, 2026 |
Get instant alerts for linux linux
Be the first to know when new high vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H