Use-After-Free Vulnerability in Linux Kernel Affecting FPGA Regions
CVE-2026-64249

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-64249?

A use-after-free vulnerability was discovered in the Linux kernel's FPGA region management. This flaw occurs in the function 'child_regions_with_firmware()' where a reference to a freed memory region may be accessed after an error has been logged. To mitigate this issue, the location of the memory release operation has been adjusted to ensure that all error handling occurs before the memory is freed, eliminating the risk of referencing invalid memory during error printouts.

Affected Version(s)

Linux 0fa20cdfcc1f68847cdfc47824476301eedc8297

Linux 0fa20cdfcc1f68847cdfc47824476301eedc8297 < 866184fc7ae42a0070f1141ae8c5dca7c24a59e2

Linux 0fa20cdfcc1f68847cdfc47824476301eedc8297 < 070b0ce947b18fa3dec0729695147f7e19599649

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.