CVE-2026-68371: Linux
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Do not put borrowed of_node in probe omap2430_probe() stores pdev->dev.of_node in a local np variable. This is a borrowed pointer and the probe function does not take a reference to it. The success and error paths nevertheless call of_node_put(np). This drops a reference that is owned by the platform device, and can leave pdev->dev.of_node with an unbalanced reference count. Do not put the borrowed platform device node from omap2430_probe(). References taken for the child MUSB device are handled by the device core, and the ctrl-module phandle reference is still released separately.
Affected products
- Linux Linux: from 6.1.2, before 6.1.184 (fixed in 6.1.184); from 6.0.16, before 6.1 (fixed in 6.1); from 6.2, before 6.6.151 (fixed in 6.6.151); from 6.7, before 6.12.101 (fixed in 6.12.101); from 6.13, before 6.18.42 (fixed in 6.18.42); from 6.19, before 7.1.6 (fixed in 7.1.6)
Published 2026-08-10. Last modified 2026-08-23.