Executive brief
A vulnerability was identified in the Linux kernel's power management component for LinkStation devices. This flaw could potentially lead to a system crash or unpredictable behavior during the system initialization process. It specifically affects how the system handles hardware identification data during startup.
Technical details
A use-after-free vulnerability exists in the linkstation_poweroff_init() function within drivers/power/reset/linkstation-poweroff.c. The root cause is an incorrect sequence of operations where of_node_put(dn) was called before of_match_node(ls_poweroff_of_match, dn), which still required the node pointer. An attacker with local access could potentially exploit this memory corruption to cause a denial of service (system crash). The issue has been resolved by reordering the function calls to ensure the node reference is only released after its final use. Patches are available in various stable kernel branches including 5.15.211, 6.1.177, 6.6.144, 6.12.95, and 6.18.38.
Affected products
- Linux Linux 5.15 to 5.15.211, 6.1 to 6.1.177, 6.6 to 6.6.144, 6.12 to 6.12.95, 6.18 to 6.18.38
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory
References
- https://git.kernel.org/stable/c/2205275be9be981e70ff29610b0117d8853fac70
- https://git.kernel.org/stable/c/3928ae803dee044b01076c478c279c0bd54164cd
- https://git.kernel.org/stable/c/8eec545cde69e46e9a1d2b7d915ce4f5df85b3bd
- https://git.kernel.org/stable/c/93c7ee139721936b6fa717572e74d3994603ae13
- https://git.kernel.org/stable/c/c04d606f8b35ee7d3ed243f63893a607e9d6c0bc
- https://git.kernel.org/stable/c/cdda7d384c05485a232ae9a849f6445accb095bf
- https://git.kernel.org/stable/c/d109e72f3fbccb540473285d17d7519584f7f76e