CVE-2025-39882
HIGHLinux Kernel 6.6.105-6.6.106, 6.12.45-6.12.47, 6.16.5-6.16.7 - Use-After-Free in DRM Mediatek OF Node Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: fix potential OF node use-after-free The for_each_child_of_node() helper drops the reference it takes to each node as it iterates over children and an explicit of_node_put() is only needed when exiting the loop early. Drop the recently introduced bogus additional reference count decrement at each iteration that could potentially lead to a use-after-free.
References (4)
Core 4
Core References
Scores
CVSS v3
7.8
EPSS
0.0014
EPSS Percentile
3.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-416
Status
published
Products (12)
linux/Kernel
6.12.45 - 6.12.48linux
linux/Kernel
6.16.5 - 6.16.8linux
linux/Kernel
6.6.105 - 6.6.107linux
Linux/Linux
1f403699c40f0806a707a9a6eed3b8904224021a - 4de37a48b6b58faaded9eb765047cf0d8785ea18
Linux/Linux
31ce7c089b50c3d3056c37e0e25e7535e4428ae1 - b58a26cdd4795c1ce6a80e38e9348885555dacd6
Linux/Linux
6.12.45 - 6.12.48
Linux/Linux
6.16.5 - 6.16.8
Linux/Linux
6.6.105 - 6.6.107
Linux/Linux
7d98166183d627c0b9daca7672b2191fae0f8a03 - b2fbe0f9f80b9cfa1e06ddcf8b863d918394ef1d
Linux/Linux
fae58d0155a979a8c414bbc12db09dd4b2f910d0 - c4901802ed1ce859242e10af06e6a7752cba0497
... and 2 more
Published
Sep 23, 2025
Tracked Since
Feb 18, 2026