CVE-2026-45925: thermal/of: Fix reference leak in thermal_of_cm_lookup()
In the Linux kernel, the following vulnerability has been resolved:
thermal/of: Fix reference leak in thermalofcmlookup()
In thermalofcmlookup(), trnp is obtained via ofparsephandle(), but never released.
Use the free(devicenode) cleanup attribute to automatically release the node and fix the leak.
[ rjw: Changelog edits ]
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Upgrade the Linux kernel to the version that includes the fix “thermal/of: Fix reference leak in thermal_of_cm_lookup()” (addresses the missing __free(device_node) cleanup attribute to prevent the of_parse_phandle() reference leak).