Linux Kernel Vulnerability in Device Property Management
CVE-2026-64220

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-64220?

A vulnerability exists in the Linux kernel's handling of firmware nodes, particularly regarding their initialization. When a firmware node is allocated on the stack or heap using a non-zeroing allocation function and is subsequently initialized via fwnode_init(), the secondary pointer may reference uninitialized memory. This condition risks unintended dereferencing, which could lead to unpredictable behavior and security issues. Proper initialization by setting fwnode->secondary to NULL is essential to mitigate this risk.

Affected Version(s)

Linux 01bb86b380a306bd937c96da36f66429f3362137

Linux 01bb86b380a306bd937c96da36f66429f3362137 < 3f1024deeab3b5443c29b3de4fe475e87309b8fa

Linux 01bb86b380a306bd937c96da36f66429f3362137 < 371f53925a6714d0aa35f1aefdffc3e8cd62f480

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.