AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-68461

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of firmware nodes, specifically in the initialization of the `fwnode_handle` structure. If a firmware node is allocated without zeroing the memory, it may contain uninitialized data, leading to potential dereferencing of invalid pointers, which can cause undefined behavior or crashes. Linux system administrators and developers should prioritize addressing this issue to ensure system stability and security.

CVE
CVE-2026-68461
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: device property: initialize the remaining fields of fwnode_handle in fwnode_init() If a firmware node is allocated on the stack (for instance: temporary software node whose life-time we control) or on the heap - but using a non-zeroing allocation function - and initialized using fwnode_init(), its secondary pointer will contain uninitialized memory which likely will be neither NULL nor IS_ERR() and so may end up being dereferenced (for example: in dev_to_swnode()). Set fwnode->secondary to NULL on initialization. While at it: initialize the remaining fields of struct fwnode_handle too just to be sure. [ Fix typo in commit message. - Danilo ]