CVE-2026-64251
CVE CVE-2026-64251EUVD EUVD-2026-48660Published 2026-07-24T15:31:17.000ZLast changed 2026-08-05T12:40:17.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() pwrseq_debugfs_seq_next() declares 'next' with __free(put_device), which causes put_device() to be called on the returned pointer when the variable goes out of scope. This results in a use-after-free since the seq_file framework receives a pointer whose reference has already been dropped. Simply removing __free(put_device) would fix the UAF but would leak the reference acquired by bus_find_next_device(), as stop() only calls up_read(&pwrseq_sem) and never releases the device reference. Fix this by making the reference counting consistent across all seq_file callbacks, matching the standard pattern used by PCI and SCSI: - start(): use get_device() so it returns a referenced pointer. - next(): explicitly put_device(curr) to release the previous device's reference (no NULL check needed - the seq_file framework only calls next() while the previous return was non-NULL). - stop(): put_device(data) to release the last iterated device's reference, with a NULL guard since stop() may be called with NULL when start() returned NULL or next() reached end-of-sequence.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.2-rc1; patch: 0; 249ebf3f65f8530beb2cbfb91bff1d83ba88d23c <e91df6d273445c03f5aa302bfe147eda33d45794; 249ebf3f65f8530beb2cbfb91bff1d83ba88d23c <73569a44fca2992f0ca4a4c0104069741b9873a0; 249ebf3f65f8530beb2cbfb91bff1d83ba88d23c <257595adf9dac15ae1edd9d07753fbc576a7583d; patch: 6.18.38; 249ebf3f65f8530beb2cbfb91bff1d83ba88d23c <ba0b9f04c7a5f9887b8ce672eaf049502c0548ec; patch: 7.1.3; patch: 6.12.95; 6.11
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.