Use-After-Free Vulnerability in Linux Kernel Affecting LinkStation Products
CVE-2026-64246

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-64246?

A use-after-free vulnerability exists in the Linux kernel specifically within the linkstation_poweroff_init() function. This issue arises from the improper management of the node reference associated with the device tree. After invoking of_match_node(), there is a move of node reference release that can lead to unsafe memory access, potentially allowing an attacker to exploit this flaw. The vulnerability has been corrected by ensuring the node reference is released only after all necessary operations are completed, thus improving the kernel's stability and security.

Affected Version(s)

Linux e2f471efe1d607a7aff38ce53ec717cebe4283d6 < 93c7ee139721936b6fa717572e74d3994603ae13

Linux e2f471efe1d607a7aff38ce53ec717cebe4283d6

Linux e2f471efe1d607a7aff38ce53ec717cebe4283d6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.