In the Linux kernel, the following vulnerability has been resolved:
riscv: Prevent a bad reference count on CPU nodes
When populating cache leaves we previously fetched the CPU device node at the very beginning. But when ACPI is enabled we go through a specific branch which returns early and does not call 'of_node_put' for the node that was acquired.
Since we are not using a CPU device node for the ACPI code anyways, we can simply move the initialization of it just passed the ACPI block, and we are guaranteed to have an 'of_node_put' call for the acquired node. This prevents a bad reference count of the CPU device node.
Moreover, the previous function did not check for errors when acquiring the device node, so a return -ENOENT has been added for that case.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-6.11.0-1009-gcpUpgrade linux-image-6.11.0-1011-oracleUpgrade linux-image-6.11.0-1009-azure-fdeUpgrade linux-image-lowlatencyUpgrade linux-image-6.11.0-1009-azureUpgrade linux-image-6.11.0-1011-oracle-64kUpgrade linux-image-generic-64kUpgrade linux-image-oem-24.04bUpgrade linux-image-gcpUpgrade linux-image-azure-fdeUpgrade linux-image-genericUpgrade linux-image-lowlatency-64kUpgrade linux-image-6.11.0-1005-realtimeUpgrade linux-image-6.11.0-18-genericUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-oem-24.04aUpgrade linux-image-virtualUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-6.11.0-1015-oemUpgrade linux-image-realtimeUpgrade linux-image-awsUpgrade linux-image-azureUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-oem-24.04Upgrade linux-image-6.11.0-1009-awsUpgrade linux-image-6.11.0-1008-raspiUpgrade linux-image-oracle-64kUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-oracleUpgrade linux-image-6.11.0-1010-lowlatencyUpgrade linux-image-6.11.0-1010-lowlatency-64kUpgrade linux-image-6.11.0-18-generic-64kUpgrade linux-image-raspi | Feb 20, 2025 | Nov 19, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub