CVE-2026-46288

In the Linux kernel, the following vulnerability has been resolved: of: unittest: fix use-after-free in of_unittest_changeset() The variable 'parent' is assigned the value of 'nchangeset' earlier in the function, meaning both point to the same struct device_node. The call to of_node_put(nchangeset) can decrement the reference count to zero and free the node if there are no other holders. After that, the code still uses 'parent' to check for the presence of a property and to read a string property, leading to a use-after-free. Fix this by moving the of_node_put() call after the last access to 'parent', avoiding the UAF.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: of: unittest: corregir uso después de liberación en of_unittest_changeset() La variable 'parent' se le asigna el valor de 'nchangeset' anteriormente en la función, lo que significa que ambos apuntan a la misma estructura device_node. La llamada a of_node_put(nchangeset) puede decrementar el contador de referencias a cero y liberar el nodo si no hay otros poseedores. Después de eso, el código todavía usa 'parent' para verificar la presencia de una propiedad y para leer una propiedad de cadena, lo que lleva a un uso después de liberación. Solucione esto moviendo la llamada a of_node_put() después del último acceso a 'parent', evitando el UAF.

08 Jul 2026, 19:04

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/37318d1a27c9cc5a70d3cd7e49e30ec86f2b8ca1 - () https://git.kernel.org/stable/c/37318d1a27c9cc5a70d3cd7e49e30ec86f2b8ca1 - Patch
References () https://git.kernel.org/stable/c/6fdad20b7975bdc32e85b45f8f7c640f6687b81f - () https://git.kernel.org/stable/c/6fdad20b7975bdc32e85b45f8f7c640f6687b81f - Patch
References () https://git.kernel.org/stable/c/7f0f0926f3010b10cff5e93446258f971e42f2fd - () https://git.kernel.org/stable/c/7f0f0926f3010b10cff5e93446258f971e42f2fd - Patch
References () https://git.kernel.org/stable/c/faecdd423c27f0d6090156a435ba9dbbac0eaddb - () https://git.kernel.org/stable/c/faecdd423c27f0d6090156a435ba9dbbac0eaddb - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-416
First Time Linux linux Kernel
Linux

14 Jun 2026, 06:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4

08 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 17:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-46288

Mitre link : CVE-2026-46288

CVE.ORG link : CVE-2026-46288


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free