CVE-2026-68371 (GCVE-0-2026-68371)
Vulnerability from cvelistv5
Published
2026-08-10 12:03
Modified
2026-08-23 12:46
Summary
In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Do not put borrowed of_node in probe omap2430_probe() stores pdev->dev.of_node in a local np variable. This is a borrowed pointer and the probe function does not take a reference to it. The success and error paths nevertheless call of_node_put(np). This drops a reference that is owned by the platform device, and can leave pdev->dev.of_node with an unbalanced reference count. Do not put the borrowed platform device node from omap2430_probe(). References taken for the child MUSB device are handled by the device core, and the ctrl-module phandle reference is still released separately.
Impacted products
Vendor Product Version
Linux Linux Version: 22b60658a90260e3fbd57824e3afe5682c6afcf5
Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec
Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec
Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec
Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec
Version: ffbe2feac59b37c8dc536727552b4f375e1b9aec
Version: fed43efc00ba6ac8c6b95828cd5acfa3d45eca4d
Version: 6.1.2   
Version: 6.0.16   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/usb/musb/omap2430.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "f0e68402d13cd9ffb289da50e65d4429d0002174",
              "status": "affected",
              "version": "22b60658a90260e3fbd57824e3afe5682c6afcf5",
              "versionType": "git"
            },
            {
              "lessThan": "eed56f105a7f70cbcfceb4df6deb6870fc58214d",
              "status": "affected",
              "version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
              "versionType": "git"
            },
            {
              "lessThan": "58d1c81c0b54a0b9aa6d6af077b09aa2f1bd2193",
              "status": "affected",
              "version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
              "versionType": "git"
            },
            {
              "lessThan": "0950ac52426b0ab32d3b8cf4afe1711668b19cb8",
              "status": "affected",
              "version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
              "versionType": "git"
            },
            {
              "lessThan": "6c525c851e5912b9753622d796f2bc55c4913b04",
              "status": "affected",
              "version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
              "versionType": "git"
            },
            {
              "lessThan": "c947360ae63eee1c9eacc030dd6f5a53f717addf",
              "status": "affected",
              "version": "ffbe2feac59b37c8dc536727552b4f375e1b9aec",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fed43efc00ba6ac8c6b95828cd5acfa3d45eca4d",
              "versionType": "git"
            },
            {
              "lessThan": "6.1.184",
              "status": "affected",
              "version": "6.1.2",
              "versionType": "semver"
            },
            {
              "lessThan": "6.1",
              "status": "affected",
              "version": "6.0.16",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/usb/musb/omap2430.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "lessThan": "6.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.184",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.184",
                  "versionStartIncluding": "6.1.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.151",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.101",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.42",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.6",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.0.16",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: musb: omap2430: Do not put borrowed of_node in probe\n\nomap2430_probe() stores pdev-\u003edev.of_node in a local np variable. This is\na borrowed pointer and the probe function does not take a reference to\nit.\n\nThe success and error paths nevertheless call of_node_put(np). This drops\na reference that is owned by the platform device, and can leave\npdev-\u003edev.of_node with an unbalanced reference count.\n\nDo not put the borrowed platform device node from omap2430_probe().\nReferences taken for the child MUSB device are handled by the device core,\nand the ctrl-module phandle reference is still released separately."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - omap2430_probe() is reached only via the local driver model - boot-time platform bus match on the OMAP MUSB device-tree node, deferred-probe retries, sysfs bind/unbind of musb-omap2430, or module load/unload. There is no network, adjacent-network, or remote path, and leveraging the prematurely released kobject name/OF node requires local heap manipulation in the same kmalloc cache.\nAC:L - The stray of_node_put(np) is unconditional on both the success return and the err_put_musb error path, so every probe invocation drops a reference the driver never took. There is no race to win, no timing window, and no memory-layout precondition; the imbalance occurs deterministically on each probe and reproduces at will through bind/unbind cycles.\nPR:N - No credential, capability, or namespace check exists on the path - the platform bus binds the OMAP MUSB node and drops the reference during kernel boot, before any user session exists, so the underflowed device_node state arises with zero privileges. Deliberate re-triggering via sysfs unbind would need root, but that is not needed for the vulnerable condition to occur.\nUI:N - The musb-omap2430 platform driver binds automatically when the device-tree node is populated, and deferred-probe retries run unattended during boot; no administrator action, victim interaction, mount, or file open is required for the unbalanced of_node_put() to execute.\nS:U - The corrupted struct device_node, its embedded kobject, and the OF tree all belong to the kernel\u0027s own security authority, and the faulting code runs in that same kernel context. No hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - The premature release drives kobject_cleanup(), which kfree_const()s kobj-\u003ename while the device_node stays reachable via pdev-\u003edev.of_node, the OF tree, and phandle lookups, so later kobject_name()/sysfs/%pOF accesses read back reclaimed heap contents an attacker can spray. The bad of_node_put() splat with dump_stack() additionally leaks kernel pointers and a full stack trace.\nI:H - A device_node whose backing kobject has been released and whose slab-allocated name has been freed yields write primitives once the memory is reclaimed: the embedded fwnode_handle.ops table is dereferenced by fwnode_call_int_op(), kobj.ktype-\u003erelease is invoked on the next put, and the parent/child/sibling and device-link list heads permit list-manipulation writes during OF tree operations.\nA:H - Reaching zero produces \"ERROR: of_node_release() detected bad of_node_put()\" with dump_stack(), and the next get/put triggers a refcount_t underflow; use-after-free WARN - an outright panic under panic_on_warn. __kobject_del() also tears down the node\u0027s /sys/firmware/devicetree entries and cascades puts onto the parent node, and dereferencing the released node oopses the kernel."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-23T12:46:19.885Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f0e68402d13cd9ffb289da50e65d4429d0002174"
        },
        {
          "url": "https://git.kernel.org/stable/c/eed56f105a7f70cbcfceb4df6deb6870fc58214d"
        },
        {
          "url": "https://git.kernel.org/stable/c/58d1c81c0b54a0b9aa6d6af077b09aa2f1bd2193"
        },
        {
          "url": "https://git.kernel.org/stable/c/0950ac52426b0ab32d3b8cf4afe1711668b19cb8"
        },
        {
          "url": "https://git.kernel.org/stable/c/6c525c851e5912b9753622d796f2bc55c4913b04"
        },
        {
          "url": "https://git.kernel.org/stable/c/c947360ae63eee1c9eacc030dd6f5a53f717addf"
        }
      ],
      "title": "usb: musb: omap2430: Do not put borrowed of_node in probe",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-68371",
    "datePublished": "2026-08-10T12:03:49.287Z",
    "dateReserved": "2026-07-30T09:28:09.386Z",
    "dateUpdated": "2026-08-23T12:46:19.885Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…