CVE-2026-90288
7.4
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
phy: renesas: rcar-gen2: Fix double of_node_put on phy creation failure
for_each_child_of_node_scoped() releases the node reference on scope exit, so the explicit of_node_put(np) in the devm_phy_create() error path drops it twice.
Drop the redundant of_node_put() and let the scoped cleanup handle it.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | b64b32791fb557f922beebddf74c47baf338cef0 < 5374f3d53376d35085e0727c8c1b945bf7123996 | affected |
| Linux | Linux | b64b32791fb557f922beebddf74c47baf338cef0 < b780b8929c759cfa7a892d58625a5ad46cb1cbd2 | affected |
| Linux | Linux | 7.0 | affected |
| Linux | Linux | 0 < 7.0 | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/5374f3d53376d35085e0727c8c1b945bf7123996
- https://git.kernel.org/stable/c/b780b8929c759cfa7a892d58625a5ad46cb1cbd2
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.