CVE-2026-45989: of: unittest: fix use-after-free in testdrv_probe()

Published May 27, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

of: unittest: fix use-after-free in testdrvprobe()

The function testdrvprobe() retrieves the devicenode from the PCI device, applies an overlay, and then immediately calls ofnodeput(dn). This releases the reference held by the PCI core, potentially freeing the node if the reference count drops to zero. Later, the same freed pointer 'dn' is passed to ofplatformdefaultpopulate(), leading to a use-after-free.

The reference to pdev->dev.ofnode is owned by the device model and should not be released by the driver. Remove the erroneous ofnodeput() to prevent premature freeing.

Affected Software

6 affected componentsFixes available
Linux Foundation Linux Kernel
Linux Linux kernel>=6.6<6.6.140
Linux Linux kernel>=6.7<6.12.86
Linux Linux kernel>=6.13<6.18.27
Linux Linux kernel>=6.19<7.0.4
Microsoft azl3 kernel 6.6.139.1-1<6.6.141.1-1
6.6.141.1-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.6.141.1-1
  2. Upgrade

    Upgrade Linux kernel (of: unittest: fix use-after-free in testdrv_probe) to a version that resolves this vulnerability.

    Patch of: unittest: fix use-after-free in testdrv_probe()

Event History

May 27, 2026
CVE Published
via MITRE·12:55 PM
Data Sourced
via MITRE·12:55 PM
Description
Data Sourced
via NVD·02:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 28, 2026
Data Sourced
via Microsoft·08:04 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:04 AM
Affected Software
Updated
via Microsoft·08:04 AM
DescriptionSeverity
Apr 4, 58427
Event
via NVD·06:45 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-45989?

The severity of CVE-2026-45989 is rated at 44.

2

What is CVE-2026-45989 related to?

CVE-2026-45989 is related to a use-after-free vulnerability in the Linux kernel's testdrv_probe() function.

3

How do I fix CVE-2026-45989?

To fix CVE-2026-45989, update to the patched version of the Linux kernel provided by the Linux Foundation.

4

How does CVE-2026-45989 impact system security?

CVE-2026-45989 can potentially lead to system instability and unauthorized access due to improper memory handling.

5

What is the function involved in CVE-2026-45989?

The function involved in CVE-2026-45989 is testdrv_probe() within the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203