CVE-2026-45925: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: thermal/of: Fix reference leak in thermal_of_cm_lookup() In thermal_of_cm_lookup(), tr_np is obtained via of_parse_phandle(), but never released. Use the __free(device_node) cleanup attribute to automatically release the node and fix the leak. [ rjw: Changelog edits ]
Affected products
- Linux Linux Kernel: from 6.12.18, before 6.12.75 (fixed in 6.12.75); from 6.13.6, before 6.14 (fixed in 6.14); from 6.14.1, before 6.18.14 (fixed in 6.18.14); from 6.19, before 6.19.4 (fixed in 6.19.4); version 6.14 only
Published 2026-05-27. Last modified 2026-06-25.