Use-After-Free Vulnerability in Linux Kernel Affecting LinkStation Products
CVE-2026-64246
What is CVE-2026-64246?
A use-after-free vulnerability exists in the Linux kernel specifically within the linkstation_poweroff_init() function. This issue arises from the improper management of the node reference associated with the device tree. After invoking of_match_node(), there is a move of node reference release that can lead to unsafe memory access, potentially allowing an attacker to exploit this flaw. The vulnerability has been corrected by ensuring the node reference is released only after all necessary operations are completed, thus improving the kernel's stability and security.
Affected Version(s)
Linux e2f471efe1d607a7aff38ce53ec717cebe4283d6 < 93c7ee139721936b6fa717572e74d3994603ae13
Linux e2f471efe1d607a7aff38ce53ec717cebe4283d6
Linux e2f471efe1d607a7aff38ce53ec717cebe4283d6