What is CVE-2026-64220?
A vulnerability was discovered in the Linux kernel's device property subsystem, where the `fwnode_init()` function does not properly set the `fwnode->secondary` pointer to NULL for firmware nodes allocated on the stack or via non-zeroing memory allocations. This leads to a risk of uninitialized memory access, potentially allowing an attacker to read sensitive kernel memory contents. Applying the kernel update is recommended for affected systems.
Azərbaycanca: Linux kernel-də `device property` alt sistemində aşkar edilmiş boşluqdur. `fwnode_init()` funksiyası, yığın (stack) və ya sıfırlamayan (non-zeroing) yaddaş sahəsində yaradılmış proqram təminatı node-ları üçün `fwnode->secondary` göstəricisini NULL olaraq təyin etmədiyi üçün istifadə olunmuş yaddaşın oxunması (uninitialized memory access) riski yaradır. Bu zəiflikdən istifadə edən hücumçu potensial olaraq kernel yaddaşından həssas məlumatları oxuya bilər. Təsirə məruz qalan sistemlərdə kernel yeniləməsinin tətbiqi tövsiyə olunur.
FAQ2
In which subsystem of the Linux kernel was CVE-2026-64220 discovered?
This vulnerability was discovered in the `device property` subsystem of the Linux kernel.
What can an attacker potentially achieve by exploiting CVE-2026-64220?
An attacker can potentially read sensitive kernel memory contents due to the risk of uninitialized memory access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.