CVE-2026-63906: Linux

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Fix use-after-free in omap2430_probe() In omap2430_probe(), of_node_put(np) is called prematurely before the last access to np, leading to a use-after-free if the node's reference count drops to zero. Move the of_node_put() calls after the last use of np in both the success and error paths.

Affected products

  • Linux Linux: from 6.1.2, before 6.1.176 (fixed in 6.1.176); from 6.0.16, before 6.1 (fixed in 6.1); from 6.2, before 6.6.143 (fixed in 6.6.143); from 6.7, before 6.12.93 (fixed in 6.12.93); from 6.13, before 6.18.35 (fixed in 6.18.35); from 6.19, before 7.0.12 (fixed in 7.0.12)

Published 2026-07-19. Last modified 2026-07-27.