PT-2026-47379 · Linux+2 · Linux Kernel+2

CVE-2026-46308

·

Published

2026-04-27

·

Updated

2026-09-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the scpsys get bus protection legacy() function. The of find node with property() function returns a device node with an incremented reference count, but of node put(node) is called before verifying if syscon regmap lookup by phandle() returns an error. If an error occurs, dev err probe() attempts to dereference the node pointer to print diagnostic information; however, the node memory may have already been freed, leading to the use-after-free condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13882
CVE-2026-46308
OPENSUSE-SU-2026:11014-1
USN-8566-1
USN-8568-1
USN-8569-1
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu