Junglewise Threat Intelligence

CVE-2026-45925: Linux Kernel reference leak in thermal_of_cm_lookup

CVE-2026-45925 · Severity: info · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's thermal management component where system resources were not properly released after use. This type of flaw, known as a reference leak, can lead to gradual memory exhaustion or system instability over time. While primarily a technical maintenance issue, it could theoretically be used to impact the availability of the operating system.

Technical details

A reference leak exists in the Linux kernel's 'thermal/of' component within the thermal_of_cm_lookup() function. The vulnerability occurs because a device node handle (tr_np) obtained via of_parse_phandle() is never released using of_node_put() or an equivalent cleanup mechanism. This results in a reference count leak for the associated device node. An attacker with local access could potentially exploit this to cause resource exhaustion. The fix implements the __free(device_node) cleanup attribute to ensure the node is automatically released when it goes out of scope.

Affected products

  • Linux Linux kernel Fixed in versions 025796c, 8344d5d, 8af7101, a1fe789

Timeline

  • 2026-01-24: other: Patch authored
  • 2026-05-27: advisory: NVD publication date

References

Related threats