Description
In the Linux kernel, the following vulnerability has been resolved:

phy: renesas: rcar-gen2: Fix double of_node_put on phy creation failure

for_each_child_of_node_scoped() releases the node reference on scope
exit, so the explicit of_node_put(np) in the devm_phy_create() error
path drops it twice.

Drop the redundant of_node_put() and let the scoped cleanup handle it.
Published: 2026-09-17
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption with potential local privilege escalation.
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a double decrement of a reference count when a phy device fails to be created. This double of_node_put leads to a double free of a device‑tree node object, which in a kernel context can corrupt memory and possibly enable arbitrary code execution or cause a crash. The bug occurs during the error path of devm_phy_create() in the Renesas rcar‑gen2 phy driver. The fix removes the redundant of_node_put so the scoped cleanup handles the release.

Affected Systems

Affected systems are Linux kernel installations that include the Renesas rcar‑gen2 PHY driver. The exact kernel releases are not listed, but any kernel that uses the rcar‑gen2 driver prior to the commit removing the double free is vulnerable. All Linux distributions that ship such kernels with this driver are impacted until they apply the kernel patch. The vendor list shows Linux by Linux, indicating the vulnerability is in the core kernel code.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity for a kernel memory‑corruption bug. The EPSS score is less than 1 %, showing the likelihood of exploitation is very low under current exposure data. The vulnerability is NOT listed in CISA’s KEV catalog. An attacker would likely need local or remote code that can execute privileged kernel code, such as manipulating device tree data, enabling the faulty driver, or exploiting a boot‑time scenario. Since the bug is a double free, the exploit could cause a denial of service or, if leveraged, may lead to privilege escalation. The attack vector is inferred as local and requires the ability to influence the device tree or kernel module loading path.

Generated by OpenCVE AI on September 20, 2026 at 00:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the rcar‑gen2 PHY driver patch that removes the duplicate of_node_put.
  • If a kernel update is not immediately possible, disable the Renesas rcar‑gen2 PHY subsystem by removing or disabling the corresponding module or device‑tree definitions to prevent the buggy code from executing.
  • Enable kernel hardening options (e.g., CONFIG_KASLR, CONFIG_SMEP/SMAP) to make exploitation of memory corruption more difficult while the patch is outstanding.

Generated by OpenCVE AI on September 20, 2026 at 00:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415
CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: phy: renesas: rcar-gen2: Fix double of_node_put on phy creation failure for_each_child_of_node_scoped() releases the node reference on scope exit, so the explicit of_node_put(np) in the devm_phy_create() error path drops it twice. Drop the redundant of_node_put() and let the scoped cleanup handle it.
Title phy: renesas: rcar-gen2: Fix double of_node_put on phy creation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:17.876Z

Reserved: 2026-09-11T19:38:34.798Z

Link: CVE-2026-90288

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:25.860

Modified: 2026-09-18T18:17:51.750

Link: CVE-2026-90288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:13Z

Weaknesses