CVE-2026-64220: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: device property: set fwnode->secondary to NULL in fwnode_init() If a firmware node is allocated on the stack (for instance: temporary software node whose life-time we control) or on the heap - but using a non-zeroing allocation function - and initialized using fwnode_init(), its secondary pointer will contain uninitalized memory which likely will be neither NULL nor IS_ERR() and so may end up being dereferenced (for example: in dev_to_swnode()). Set fwnode->secondary to NULL on initialization.

Affected products

  • Linux Linux Kernel: from 5.11, before 5.15.209 (fixed in 5.15.209); from 5.16, before 6.1.175 (fixed in 6.1.175); from 6.2, before 6.6.142 (fixed in 6.6.142); from 6.7, before 6.12.92 (fixed in 6.12.92); from 6.13, before 6.18.34 (fixed in 6.18.34); from 6.19, before 7.0.11 (fixed in 7.0.11); …

Published 2026-07-24. Last modified 2026-08-11.