CVE-2025-39882: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: fix potential OF node use-after-free The for_each_child_of_node() helper drops the reference it takes to each node as it iterates over children and an explicit of_node_put() is only needed when exiting the loop early. Drop the recently introduced bogus additional reference count decrement at each iteration that could potentially lead to a use-after-free.
Affected products
- Linux Linux Kernel: from 6.6.105, before 6.6.107 (fixed in 6.6.107); from 6.12.45, before 6.12.48 (fixed in 6.12.48); from 6.16.5, before 6.16.8 (fixed in 6.16.8); version 6.17 only
Published 2025-09-23. Last modified 2026-07-30.