{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68461","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.395Z","datePublished":"2026-08-15T05:51:21.219Z","dateUpdated":"2026-08-17T05:39:08.142Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:39:08.142Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndevice property: initialize the remaining fields of fwnode_handle in fwnode_init()\n\nIf a firmware node is allocated on the stack (for instance: temporary\nsoftware node whose life-time we control) or on the heap - but using a\nnon-zeroing allocation function - and initialized using fwnode_init(),\nits secondary pointer will contain uninitialized memory which likely\nwill be neither NULL nor IS_ERR() and so may end up being dereferenced\n(for example: in dev_to_swnode()). Set fwnode->secondary to NULL on\ninitialization. While at it: initialize the remaining fields of struct\nfwnode_handle too just to be sure.\n\n[ Fix typo in commit message. - Danilo ]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The flaw is in fwnode_init() in the driver-core firmware-node layer; uninitialized fwnode->secondary is consumed in dev_to_swnode() and fwnode_property_*() during local device probe, property lookups, and configfs-driven gpio-sim/gpio-virtuser software-node creation—never from a network packet or remote protocol handler.\nAC:L - Once a fwnode_handle is placed in non-zeroed stack or kmalloc storage and passed through fwnode_init(), the uninitialized secondary pointer is deterministically non-NULL and non-IS_ERR(), and property helpers immediately pass it to fwnode_call_*_op() without further validation—no race, heap grooming, or victim timing is required.\nPR:L - No init-namespace root is required to reach the dereference paths: fwnode_property_present() and dev_to_swnode() run during automatic driver probe/bind and consumer property resolution (GPIO/IIO/reset/v4l2-fwnode) that a local unprivileged user can trigger by opening device nodes or causing driver binding on embedded/Android systems using software nodes.\nUI:N - The garbage secondary pointer is dereferenced automatically inside kernel property lookups and dev_to_swnode() during probe or device registration; no separate victim action such as mounting media, clicking a prompt, or opening a malicious file is needed beyond the affected driver path executing.\nS:U - Impact is confined to kernel memory corruption and crashes within the host kernel's own security authority during firmware-node property handling; it does not cross VM, IOMMU, container, or sandbox boundaries.\nC:H - An uninitialized secondary is treated as a live fwnode_handle pointer; fwnode_call_bool_op()/fwnode_call_int_op() evaluate fwnode->ops on attacker-influenced stack or slab residue, reading kernel memory through misinterpreted ops tables rather than a bounded disclosure.\nI:H - The same garbage secondary is passed into fwnode_call_*_op() and set_secondary_fwnode()/fwnode_is_primary() logic; a non-NULL, non-ERR value with plausible ops and list-head residue enables indirect calls and list manipulation—control-flow-relevant memory corruption per CNA guidance for uninitialized pointer use in fwnode plumbing.\nA:H - Dereferencing an uninitialized secondary in dev_to_swnode() or fwnode_property_*() causes an immediate kernel oops/panic from a bad pointer or invalid ops dispatch; the fault is repeatable whenever the affected fwnode initialization path is exercised."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/linux/fwnode.h"],"versions":[{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"0198d579948322cda5178b9672d448375a32f947","status":"affected","versionType":"git"},{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"173b61c9276c7b3a5fbcc63ae7aafc897fee1e18","status":"affected","versionType":"git"},{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"f0b4e1cc8ad76baf49d898727eb52e91a4ef0544","status":"affected","versionType":"git"},{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"c8542b68ba6ef4f61072098893a3f5b71c569b6c","status":"affected","versionType":"git"},{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"9c86a1f930bb2ddb85f867b4736716e82a4a4683","status":"affected","versionType":"git"},{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"c81e2af41de6a159837c7129a4fc444ac6e48046","status":"affected","versionType":"git"},{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"7eba000621fff223dd7bab484d48918c7c77a307","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/linux/fwnode.h"],"versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.12.96"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.18.39"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0198d579948322cda5178b9672d448375a32f947"},{"url":"https://git.kernel.org/stable/c/173b61c9276c7b3a5fbcc63ae7aafc897fee1e18"},{"url":"https://git.kernel.org/stable/c/f0b4e1cc8ad76baf49d898727eb52e91a4ef0544"},{"url":"https://git.kernel.org/stable/c/c8542b68ba6ef4f61072098893a3f5b71c569b6c"},{"url":"https://git.kernel.org/stable/c/9c86a1f930bb2ddb85f867b4736716e82a4a4683"},{"url":"https://git.kernel.org/stable/c/c81e2af41de6a159837c7129a4fc444ac6e48046"},{"url":"https://git.kernel.org/stable/c/7eba000621fff223dd7bab484d48918c7c77a307"}],"title":"device property: initialize the remaining fields of fwnode_handle in fwnode_init()","x_generator":{"engine":"bippy-1.2.0"}}}}