PT-2026-47360 · Linux · Linux
Published
2026-06-08
·
Updated
2026-06-08
·
CVE-2026-46288
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
of: unittest: fix use-after-free in of unittest changeset()
The variable 'parent' is assigned the value of 'nchangeset' earlier in the
function, meaning both point to the same struct device node. The call to
of node put(nchangeset) can decrement the reference count to zero and
free the node if there are no other holders. After that, the code still
uses 'parent' to check for the presence of a property and to read a
string property, leading to a use-after-free.
Fix this by moving the of node put() call after the last access to
'parent', avoiding the UAF.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux