CVE-2026-45925

Updated on 27 May 2026

Severity

5.5 Medium severity

Details

CVSS score
5.5

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: thermal/of: Fix reference leak in thermal_of_cm_lookup() In thermal_of_cm_lookup(), tr_np is obtained via of_parse_phandle(), but never released. Use the __free(device_node) cleanup attribute to automatically release the node and fix the leak. [ rjw: Changelog edits ] A flaw was found in the Linux kernel’s thermal management module. A reference leak occurs in the thermal_of_cm_lookup() function because a device node (tr_np) obtained through of_parse_phandle() is not properly released. This issue can lead to resource exhaustion over time, potentially impacting system stability and availability.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 13 Planned