Executive brief
A vulnerability was identified in the Linux kernel's thermal management component where system resources were not properly released after use. This type of flaw, known as a reference leak, can lead to gradual memory exhaustion or system instability over time. While primarily a technical maintenance issue, it could theoretically be used to impact the availability of the operating system.
Technical details
A reference leak exists in the Linux kernel's 'thermal/of' component within the thermal_of_cm_lookup() function. The vulnerability occurs because a device node handle (tr_np) obtained via of_parse_phandle() is never released using of_node_put() or an equivalent cleanup mechanism. This results in a reference count leak for the associated device node. An attacker with local access could potentially exploit this to cause resource exhaustion. The fix implements the __free(device_node) cleanup attribute to ensure the node is automatically released when it goes out of scope.
Affected products
- Linux Linux kernel Fixed in versions 025796c, 8344d5d, 8af7101, a1fe789
Timeline
- 2026-01-24: other: Patch authored
- 2026-05-27: advisory: NVD publication date