← Späť na vyhľadávanie CVE

CVE-2026-31399

Linux Kernel

Popis

In the Linux kernel, the following vulnerability has been resolved: nvdimm/bus: Fix potential use after free in asynchronous initialization Dingisoul with KASAN reports a use after free if device_add() fails in nd_async_device_register(). Commit b6eae0f61db2 (-libnvdimm: Hold reference on parent while scheduling async init-) correctly added a reference on the parent device to be held until asynchronous initialization was complete. However, if device_add() results in an allocation failure the ref count of the device drops to 0 prior to the parent pointer being accessed. Thus resulting in use after free. The bug bot AI correctly identified the fix. Save a reference to the parent pointer to be used to drop the parent reference regardless of the outcome of device_add().

CVSS 7.8EPSS 0.11900000000000001%Riziko 0.79
Zobraziť zdroj
Zverejnené
2026-04-03 16:16:38
Dotknuté verzie
unknown
Typ
Core software
Posledná úprava
2026-07-24 22:10:00
Vektor
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Operačné systémy
Linux