CVE-2026-89504
Received Received - Intake

Memory Corruption in Linux Kernel Regulator Subsystem

Vulnerability report for CVE-2026-89504, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer In as3722_get_regulator_dt_data(), of_get_child_by_name() acquires a reference on np, which is then assigned to pdev->dev.of_node. The function immediately calls of_node_put(np), releasing the reference and leaving pdev->dev.of_node as a dangling pointer. Remove the of_node_put(np) call to let the device hold the reference.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a premature call to of_node_put() in the as3722_get_regulator_dt_data() function. The function uses of_get_child_by_name() to acquire a reference on a device node pointer (np), which is then assigned to pdev->dev.of_node. However, the function incorrectly calls of_node_put(np) immediately after, releasing the reference and leaving pdev->dev.of_node as a dangling pointer, which can cause undefined behavior or crashes.

Detection Guidance

This vulnerability is specific to the Linux kernel's regulator subsystem and involves a dangling pointer in device tree node handling. Detection requires checking kernel logs for related errors or kernel version checks. Use commands like 'dmesg | grep as3722' or 'uname -a' to inspect kernel logs and version.

Impact Analysis

This vulnerability could lead to system instability, crashes, or unexpected behavior in systems running affected versions of the Linux kernel. It may cause devices to malfunction or fail to initialize properly, potentially disrupting services that rely on the regulator subsystem.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to a Linux kernel regulator driver issue. No evidence suggests data privacy or security compliance impacts from this specific flaw.

Mitigation Strategies

Apply the latest kernel update that includes the fix for this issue. Monitor kernel security advisories and update to a patched kernel version. If using a distribution kernel, check for updates via your package manager (e.g., 'apt upgrade' or 'yum update').

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89504. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart