Executive brief
A vulnerability was identified in the Linux kernel's MediaTek power domain driver. The software incorrectly releases memory associated with a device component before it has finished using it during error handling. This could potentially lead to system instability or crashes when the system encounters specific hardware configuration errors.
Technical details
A use-after-free (UAF) vulnerability exists in drivers/pmdomain/mediatek/mtk-pm-domains.c within the scpsys_get_bus_protection_legacy() function. The function calls of_node_put(node) to decrement a reference count before checking the return value of syscon_regmap_lookup_by_phandle(). If that lookup fails, the subsequent call to dev_err_probe() attempts to dereference the 'node' pointer for diagnostic logging after it may have already been freed. This is a local vulnerability requiring the ability to trigger specific error paths in the MediaTek power domain driver. The issue has been resolved by reordering the of_node_put() call to occur after the error check.
Affected products
- Linux Linux Kernel Fixed in 38d8410, cb27e43, ec1fcdd
Timeline
- 2026-04-08: disclosed: Initial patch authored
- 2026-06-08: advisory: CVE published in NVD