Junglewise Threat Intelligence

CVE-2026-80750: Linux kernel pmdomain mediatek use-after-free in error handling

CVE-2026-80750 · Severity: high · CVSS 8.4 · Published 2026-09-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's MediaTek power domain driver contains a use-after-free vulnerability in its device-tree node handling. When certain error conditions occur during device initialization, the driver releases a reference to a device-tree node but then attempts to format and log a message using that freed node's data, potentially causing memory corruption or kernel crashes. This affects systems using MediaTek processors with this driver during boot or power domain configuration.

Technical details

The vulnerability is a use-after-free in the scpsys_get_bus_protection_legacy() function in drivers/pmdomain/mediatek/mtk-pm-domains.c. The vulnerable code calls of_node_put() to release a device-tree node reference, then passes that same node pointer to dev_err_probe() with the %pOF format specifier, which attempts to dereference the freed node object. If of_node_put() drops the last reference count, the node's memory is freed before the error message is formatted, leading to potential out-of-bounds memory access. The fix reorders the cleanup to defer of_node_put() calls until after dev_err_probe() has completed, ensuring the node remains valid during error logging. Attack vector is local and requires triggering specific device initialization error paths.

Affected products

  • Linux Linux kernel Affected by c29345fa5f66 (pmdomain: mediatek: Refactor bus protection regmaps retrieval), patched by commit 3e013bc8b941bd52c8e3a99798d0ae8792cb71ca

Timeline

  • 2026-09-03: disclosed
  • 2026-07-27: patched

References

Related threats