device property: set fwnode->secondary to NULL in fwnode_init()

Summary

CVECVE-2026-64220
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-24 16:16:49 UTC
Updated2026-07-24 16:16:49 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: device property: set fwnode->secondary to NULL in fwnode_init() If a firmware node is allocated on the stack (for instance: temporary software node whose life-time we control) or on the heap - but using a non-zeroing allocation function - and initialized using fwnode_init(), its secondary pointer will contain uninitalized memory which likely will be neither NULL nor IS_ERR() and so may end up being dereferenced (for example: in dev_to_swnode()). Set fwnode->secondary to NULL on initialization.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 01bb86b380a306bd937c96da36f66429f3362137 f0e211d6539fae800217c10797993b7592d6ab01 git Not specified
CNA Linux Linux affected 01bb86b380a306bd937c96da36f66429f3362137 3f1024deeab3b5443c29b3de4fe475e87309b8fa git Not specified
CNA Linux Linux affected 01bb86b380a306bd937c96da36f66429f3362137 371f53925a6714d0aa35f1aefdffc3e8cd62f480 git Not specified
CNA Linux Linux affected 01bb86b380a306bd937c96da36f66429f3362137 34bf74b1fd2e4a44e27821a329204caf09df2976 git Not specified
CNA Linux Linux affected 01bb86b380a306bd937c96da36f66429f3362137 508fd8ab158abd04b7f7d0f707cd6d6c405df4ea git Not specified
CNA Linux Linux affected 01bb86b380a306bd937c96da36f66429f3362137 f59e686c778cb41b8f7aa8fab2afd6a01afb3d47 git Not specified
CNA Linux Linux affected 01bb86b380a306bd937c96da36f66429f3362137 215c90ee656114f5e8c32408228d97082f8e0eef git Not specified
CNA Linux Linux affected 5.11 Not specified
CNA Linux Linux unaffected 5.11 semver Not specified
CNA Linux Linux unaffected 5.15.209 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.175 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.142 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.92 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.34 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.11 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/f0e211d6539fae800217c10797993b7592d6ab01 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/371f53925a6714d0aa35f1aefdffc3e8cd62f480 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/215c90ee656114f5e8c32408228d97082f8e0eef 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f59e686c778cb41b8f7aa8fab2afd6a01afb3d47 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/34bf74b1fd2e4a44e27821a329204caf09df2976 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/508fd8ab158abd04b7f7d0f707cd6d6c405df4ea 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3f1024deeab3b5443c29b3de4fe475e87309b8fa 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report