Executive brief
The Linux kernel's MediaTek power domain driver contains a use-after-free vulnerability in its device-tree node handling. When certain error conditions occur during device initialization, the driver releases a reference to a device-tree node but then attempts to format and log a message using that freed node's data, potentially causing memory corruption or kernel crashes. This affects systems using MediaTek processors with this driver during boot or power domain configuration.
Technical details
The vulnerability is a use-after-free in the scpsys_get_bus_protection_legacy() function in drivers/pmdomain/mediatek/mtk-pm-domains.c. The vulnerable code calls of_node_put() to release a device-tree node reference, then passes that same node pointer to dev_err_probe() with the %pOF format specifier, which attempts to dereference the freed node object. If of_node_put() drops the last reference count, the node's memory is freed before the error message is formatted, leading to potential out-of-bounds memory access. The fix reorders the cleanup to defer of_node_put() calls until after dev_err_probe() has completed, ensuring the node remains valid during error logging. Attack vector is local and requires triggering specific device initialization error paths.
Affected products
- Linux Linux kernel Affected by c29345fa5f66 (pmdomain: mediatek: Refactor bus protection regmaps retrieval), patched by commit 3e013bc8b941bd52c8e3a99798d0ae8792cb71ca
Timeline
- 2026-09-03: disclosed
- 2026-07-27: patched