All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-72179: riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
@ 2026-08-15  6:04 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-15  6:04 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

riscv: cacheinfo: Fix node reference leak in populate_cache_leaves

Currently, the while loop drops the reference to prev in each iteration.
If the loop terminates early due to a break, the final of_node_put(np)
correctly drops the reference to the current node.

However, if the loop terminates naturally because np == NULL, calling
of_node_put(np) is a no-op. This leaves the last valid node stored in
prev without its reference dropped, resulting in a node reference leak.

Fix this by changing the final `of_node_put(np)` to `of_node_put(prev)`.

The Linux kernel CVE team has assigned CVE-2026-72179 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.0 with commit 94f9bf118f1e294b3f2092f8bde02860f5e3ea3f and fixed in 6.1.178 with commit 2560c97f63bb99b26d9f19b23a4f66ea24c9dc14
	Issue introduced in 5.0 with commit 94f9bf118f1e294b3f2092f8bde02860f5e3ea3f and fixed in 6.6.145 with commit 51afb7da697b698996351740b4f39fb05ce2afd4
	Issue introduced in 5.0 with commit 94f9bf118f1e294b3f2092f8bde02860f5e3ea3f and fixed in 6.12.97 with commit 880ac50b0bfae06d7ab5f1843253adfb86aa173a
	Issue introduced in 5.0 with commit 94f9bf118f1e294b3f2092f8bde02860f5e3ea3f and fixed in 6.18.40 with commit f322955d9a1c344ed943752f05aacea7bc22e025
	Issue introduced in 5.0 with commit 94f9bf118f1e294b3f2092f8bde02860f5e3ea3f and fixed in 7.1.5 with commit 36e4843fe39ea2f17f4de6d59fba26271916c184
	Issue introduced in 5.0 with commit 94f9bf118f1e294b3f2092f8bde02860f5e3ea3f and fixed in 7.2-rc1 with commit bf4a195f063b0a0805c1417f6aad1dd32ea48f0f

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-72179
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	arch/riscv/kernel/cacheinfo.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/2560c97f63bb99b26d9f19b23a4f66ea24c9dc14
	https://git.kernel.org/stable/c/51afb7da697b698996351740b4f39fb05ce2afd4
	https://git.kernel.org/stable/c/880ac50b0bfae06d7ab5f1843253adfb86aa173a
	https://git.kernel.org/stable/c/f322955d9a1c344ed943752f05aacea7bc22e025
	https://git.kernel.org/stable/c/36e4843fe39ea2f17f4de6d59fba26271916c184
	https://git.kernel.org/stable/c/bf4a195f063b0a0805c1417f6aad1dd32ea48f0f

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-15  6:15 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-15  6:04 CVE-2026-72179: riscv: cacheinfo: Fix node reference leak in populate_cache_leaves Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.