From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CD890583ACB for ; Fri, 11 Sep 2026 19:53:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156422; cv=none; b=qjnUKbOs5V8cIG20DdZSHtN+qkXBjlYPd51urHNGei1UPhIWAEfjPABGgDUEn8JYW5JvLiTAGpfKPCTpmjHvgQFj+lu43QUgM71+Gn3qrV/s4TXgrcUo682CpYw/KieO9TQ2OwL+OD3D1f+W5YBA8o/5l0VCxwB9scIaRDQcNf4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156422; c=relaxed/simple; bh=VEOTD/7wE8ztjajKAK9qvtAZ2NeNuHpSubPQSTrWXTY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=iUbYEKULclLy+NRpXisxbT4Pa4J+SxYBazAK/cxIvldbBZgxS+vSgmFzGZAQph56RQZmneKYYUC8peFvkKvF8E6PZ4Bx4MeRsxXQF1plfVApiD+xLR5qucBo9Ylsgzl1xmpH+WNSsrjagSZFIVAoYK2SdvbpFUXKLQJdePQwABI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=TbWjIxvX; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="TbWjIxvX" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 772031F00893; Fri, 11 Sep 2026 19:53:18 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156399; bh=pYM0o4ke+XaCdAMofk1kyB905ivSWcfNyjvugUE4HBk=; h=From:To:Cc:Subject:Date:Reply-To; b=TbWjIxvXjqcE5/eHpc/mCDxLnroTqVwTtbYB3YPPWiTVCyr8mtkpQOP9D0DDKMoDR xR74SsuCMZiyxuU2IzkQWPPFAthHSD6Og7/gTOujQBLWf3UGaOti07tJbSgziZDa5z dyUPql6DVdXrUZKeFgCdmdfjyCH+tIWz3kYCapCo= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89504: regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer Date: Fri, 11 Sep 2026 21:43:13 +0200 Message-ID: <2026091110-CVE-2026-89504-2510@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2611; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=mvSLofVlMDxAPcn61wepVdwPMhlJViP+Nhq2+y2OALY=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIsPcvWfpTWj/e+y47P7Wo08OSb02LmpJKHx54Libe enaCy85O2JZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAinpcZFqzIXzzj3RnZe28W rk+aM3vPspBlvuUM88M/1rNl71dMLnJIZ2b/+uU7G0+vCwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer In as3722_get_regulator_dt_data(), of_get_child_by_name() acquires a reference on np, which is then assigned to pdev->dev.of_node. The function immediately calls of_node_put(np), releasing the reference and leaving pdev->dev.of_node as a dangling pointer. Remove the of_node_put(np) call to let the device hold the reference. The Linux kernel CVE team has assigned CVE-2026-89504 to this issue. Affected and fixed versions =========================== Issue introduced in 3.13 with commit bc407334e9a6a745de5360395282beb2690adf48 and fixed in 6.12.109 with commit d3c1316d84e0a036890b00ae6e4c0b0b80f70c25 Issue introduced in 3.13 with commit bc407334e9a6a745de5360395282beb2690adf48 and fixed in 6.18.50 with commit 95342d26f9c6b68a46ab57fa48428a3c4a423dd7 Issue introduced in 3.13 with commit bc407334e9a6a745de5360395282beb2690adf48 and fixed in 7.2.4 with commit 8648e29e5c01b6b677c704049189287e27255ccb Issue introduced in 3.13 with commit bc407334e9a6a745de5360395282beb2690adf48 and fixed in 7.3-rc1 with commit f9324d670ae0b88cbfb0aa48fcaefa5baeb8da4c Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89504 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/regulator/as3722-regulator.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/d3c1316d84e0a036890b00ae6e4c0b0b80f70c25 https://git.kernel.org/stable/c/95342d26f9c6b68a46ab57fa48428a3c4a423dd7 https://git.kernel.org/stable/c/8648e29e5c01b6b677c704049189287e27255ccb https://git.kernel.org/stable/c/f9324d670ae0b88cbfb0aa48fcaefa5baeb8da4c