Use-After-Free Vulnerability in Linux Kernel Affecting FPGA Regions
CVE-2026-64249
Currently unrated
What is CVE-2026-64249?
A use-after-free vulnerability was discovered in the Linux kernel's FPGA region management. This flaw occurs in the function 'child_regions_with_firmware()' where a reference to a freed memory region may be accessed after an error has been logged. To mitigate this issue, the location of the memory release operation has been adjusted to ensure that all error handling occurs before the memory is freed, eliminating the risk of referencing invalid memory during error printouts.
Affected Version(s)
Linux 0fa20cdfcc1f68847cdfc47824476301eedc8297
Linux 0fa20cdfcc1f68847cdfc47824476301eedc8297 < 866184fc7ae42a0070f1141ae8c5dca7c24a59e2
Linux 0fa20cdfcc1f68847cdfc47824476301eedc8297 < 070b0ce947b18fa3dec0729695147f7e19599649