PT-2026-47360 · Linux · Linux

Published

2026-06-08

·

Updated

2026-06-08

·

CVE-2026-46288

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
of: unittest: fix use-after-free in of unittest changeset()
The variable 'parent' is assigned the value of 'nchangeset' earlier in the function, meaning both point to the same struct device node. The call to of node put(nchangeset) can decrement the reference count to zero and free the node if there are no other holders. After that, the code still uses 'parent' to check for the presence of a property and to read a string property, leading to a use-after-free.
Fix this by moving the of node put() call after the last access to 'parent', avoiding the UAF.

Related Identifiers

CVE-2026-46288

Affected Products

Linux