SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-64220

MEDIUM · CVSS 5.5 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel, specifically in the handling of firmware nodes where the secondary pointer may contain uninitialized memory if allocated on the stack or heap without zeroing. This could lead to potential dereferencing of invalid memory, resulting in undefined behavior or crashes. Linux kernel developers and maintainers should prioritize this issue to ensure system stability and security.

CVE
CVE-2026-64220
Severity
MEDIUM
CVSS
5.5
EPSS
0.12%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: device property: set fwnode->secondary to NULL in fwnode_init() If a firmware node is allocated on the stack (for instance: temporary software node whose life-time we control) or on the heap - but using a non-zeroing allocation function - and initialized using fwnode_init(), its secondary pointer will contain uninitalized memory which likely will be neither NULL nor IS_ERR() and so may end up being dereferenced (for example: in dev_to_swnode()). Set fwnode->secondary to NULL on initialization.

Related CVEs

Other vulnerabilities affecting the same vendor(s)