{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-46288",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-05-13T15:03:33.110Z",
        "datePublished": "2026-06-08T15:41:31.868Z",
        "dateUpdated": "2026-08-05T12:31:02.134Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:31:02.134Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nof: unittest: fix use-after-free in of_unittest_changeset()\n\nThe variable 'parent' is assigned the value of 'nchangeset' earlier in the\nfunction, meaning both point to the same struct device_node. The call to\nof_node_put(nchangeset) can decrement the reference count to zero and\nfree the node if there are no other holders. After that, the code still\nuses 'parent' to check for the presence of a property and to read a\nstring property, leading to a use-after-free.\n\nFix this by moving the of_node_put() call after the last access to\n'parent', avoiding the UAF."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable code runs only during late_initcall boot self-tests in drivers/of/unittest.c; reaching it requires local ability to build and boot a kernel with CONFIG_OF_UNITTEST enabled, with no network, syscall, or ioctl runtime path.\nAC:L - Once the unittest kernel boots, the UAF triggers deterministically after of_changeset_revert() when of_node_put() drops the sole reference; no race or attacker-uncontrolled memory layout is required.\nPR:N - Exploitation does not require privileges on a running production system—only booting a specially built unittest kernel—so no authenticated local user or namespace capability on the target image is needed.\nUI:N - The unittest executes automatically during kernel initialization after testcase DT data is attached; no additional victim interaction beyond booting the test configuration is required.\nS:U - The UAF corrupts kernel heap memory during in-kernel device-tree self-tests and does not cross VM, sandbox, or IOMMU security boundaries.\nC:H - After of_node_put() frees the device_node, of_property_present() and of_property_read_string() dereference freed memory, enabling kernel information disclosure from attacker-influencable freed heap contents.\nI:H - Use-after-free on a struct device_node in kernel heap can be leveraged for memory corruption and arbitrary kernel code execution via heap grooming, not merely a bounded write.\nA:H - Dereferencing a freed device_node during property lookups can cause kernel oops, BUG, or panic during boot-time unittest execution."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/of/unittest.c"
                    ],
                    "versions": [
                        {
                            "version": "1c668ea65506e67ce2eae07b69bb09fcdd86e309",
                            "lessThan": "37318d1a27c9cc5a70d3cd7e49e30ec86f2b8ca1",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "1c668ea65506e67ce2eae07b69bb09fcdd86e309",
                            "lessThan": "7f0f0926f3010b10cff5e93446258f971e42f2fd",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "1c668ea65506e67ce2eae07b69bb09fcdd86e309",
                            "lessThan": "6fdad20b7975bdc32e85b45f8f7c640f6687b81f",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "1c668ea65506e67ce2eae07b69bb09fcdd86e309",
                            "lessThan": "faecdd423c27f0d6090156a435ba9dbbac0eaddb",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/of/unittest.c"
                    ],
                    "versions": [
                        {
                            "version": "6.12",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.12",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.86",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.27",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.0.4",
                            "lessThanOrEqual": "7.0.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12",
                                    "versionEndExcluding": "6.12.86"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12",
                                    "versionEndExcluding": "6.18.27"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12",
                                    "versionEndExcluding": "7.0.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12",
                                    "versionEndExcluding": "7.1"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/37318d1a27c9cc5a70d3cd7e49e30ec86f2b8ca1"
                },
                {
                    "url": "https://git.kernel.org/stable/c/7f0f0926f3010b10cff5e93446258f971e42f2fd"
                },
                {
                    "url": "https://git.kernel.org/stable/c/6fdad20b7975bdc32e85b45f8f7c640f6687b81f"
                },
                {
                    "url": "https://git.kernel.org/stable/c/faecdd423c27f0d6090156a435ba9dbbac0eaddb"
                }
            ],
            "title": "of: unittest: fix use-after-free in of_unittest_changeset()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}