CVE-2026-74519

Summary

In the Linux kernel, the following vulnerability has been resolved:

pinctrl: devicetree: don't free uninitialized dev_name on error path

dt_remember_or_free_map() duplicates dev_name for each map entry. If kstrdup_const() fails, dt_free_map() frees dev_name in all num_maps entries, including entries that have not been initialized.

Some pinctrl drivers, including pinctrl-imx, allocate the map with kmalloc() and leave dev_name for the core to initialize. The untouched entries therefore contain uninitialized data which is passed to kfree_const().

Reproduced on qemu's mcimx6ul-evk (pinctrl-imx) with failslab injection while binding the pinctrl-consuming device, under KASAN:

BUG: KASAN: double-free in dt_free_map+0x34/0xa4 Free of addr c425a900 by task init/1 kfree from dt_free_map+0x34/0xa4 dt_free_map from dt_remember_or_free_map+0x184/0x198 dt_remember_or_free_map from pinctrl_dt_to_map+0x33c/0x4c8 pinctrl_dt_to_map from create_pinctrl+0x9c/0x5c0

Initialize all dev_name fields to NULL before duplicating the device name, making the full-map cleanup safe after a partial failure.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxbe4c60b563edee3712d392aaeb0943a768df7023 < 929f6396baade89999ec8a1281232c101cbc727daffected
LinuxLinuxbe4c60b563edee3712d392aaeb0943a768df7023 < 321fe3584a8298386938130d138191aa35040b75affected
LinuxLinuxbe4c60b563edee3712d392aaeb0943a768df7023 < ad0ad3c228b6f76fde10f32047e0ec5fbc109dc8affected
LinuxLinuxbe4c60b563edee3712d392aaeb0943a768df7023 < 9d00a5ac7cd3d32ae61140f4b8a62f136de84e7daffected
LinuxLinuxbe4c60b563edee3712d392aaeb0943a768df7023 < 015b5bcbcb622b32317642be91a7f79aa5413649affected
LinuxLinux03f69244302d7954f42f528ea2d45903ebbf59f3affected
LinuxLinux77440c3a37203e3f4667d06e37f76ef3968d2d8caffected
LinuxLinux679c4f27b8958b65bb51d1c3dfdbf3befe4a33a3affected
LinuxLinuxf88ac1330779c5bfdd79f7d7f7d4d3343c782f92affected
LinuxLinuxf739a699db7d5a5cf39ca3ce2c84e4fe4a8f4c5daffected
LinuxLinux4.4.244 < 4.5affected
LinuxLinux4.9.244 < 4.10affected
LinuxLinux4.14.161 < 4.15affected
LinuxLinux4.19.92 < 4.20affected
LinuxLinux5.4.7 < 5.5affected
LinuxLinux5.5affected
LinuxLinux0 < 5.5unaffected
LinuxLinux6.6.151 <= 6.6.*unaffected
LinuxLinux6.12.103 <= 6.12.*unaffected
LinuxLinux6.18.44 <= 6.18.*unaffected
LinuxLinux7.1.8 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References