<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 01:13:03 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-80750 — pmdomain: mediatek: fix remaining %pOF after of_node_put()</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-80750</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;pmdomain: mediatek: fix remaining %pOF after of_node_put()&lt;/p&gt;
&lt;p&gt;scpsys_get_bus_protection_legacy() looks up several legacy bus
protection regmaps from device-tree nodes.&lt;/p&gt;
&lt;p&gt;Two error paths put the device node before checking whether the regmap
lookup failed, but still pass that node to dev_err_probe() with %pOF on
failure. If of_node_put() drops the last reference, the later %pOF
formatting can dereference a freed device node.&lt;/p&gt;
&lt;p&gt;Keep the node reference until after the error message has been emitted in
the infracfg and SMI lookup paths. Also drop the SMI node before
returning when the SMI phandle is missing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;pmdomain: mediatek: fix remaining %pOF after of_node_put()&lt;/p&gt;
&lt;p&gt;scpsys_get_bus_protection_legacy() looks up several legacy bus
protection regmaps from device-tree nodes.&lt;/p&gt;
&lt;p&gt;Two error paths put the device node before checking whether the regmap
lookup failed, but still pass that node to dev_err_probe() with %pOF on
failure. If of_node_put() drops the last reference, the later %pOF
formatting can dereference a freed device node.&lt;/p&gt;
&lt;p&gt;Keep the node reference until after the error message has been emitted in
the infracfg and SMI lookup paths. Also drop the SMI node before
returning when the SMI phandle is missing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-80750</guid>
    </item>
  </channel>
</rss>
