CVE-2026-23030
In the Linux kernel, the following vulnerability has been resolved:
phy: rockchip: inno-usb2: Fix a double free bug in rockchip_usb2phy_probe()
The for_each_available_child_of_node() calls of_node_put() to release child_np in each success loop. After breaking from the loop with the child_np has been released, the code will jump to the put_child label and will call the of_node_put() again if the devm_request_threaded_irq() fails. These cause a double free bug.
Fix by returning directly to avoid the duplicate of_node_put().
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.25%
- Percentil entre todas las CVEs puntuadas: 15
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/027d42b97e6eb827c3438ebc09bab7efaee9270d
- https://git.kernel.org/stable/c/b97b2c9808c9a97e0ce30216fa12096d8b0eaa75
- https://git.kernel.org/stable/c/e07dea3de508cd6950c937cec42de7603190e1ca
- https://git.kernel.org/stable/c/ebae26dd15140b840cf65be5e1c0daee949ba70b
- https://git.kernel.org/stable/c/efe92ee7a111fe0f4d75f3ed6b7e3f86322279d5
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-23030",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "ed2b5a8e6b98d042b323afbe177a5dc618921b31",
"lessThan": "b97b2c9808c9a97e0ce30216fa12096d8b0eaa75",
"versionType": "git"
},
{
"status": "affected",
"version": "ed2b5a8e6b98d042b323afbe177a5dc618921b31",
"lessThan": "ebae26dd15140b840cf65be5e1c0daee949ba70b",
"versionType": "git"
},
{
"status": "affected",
"version": "ed2b5a8e6b98d042b323afbe177a5dc618921b31",
"lessThan": "027d42b97e6eb827c3438ebc09bab7efaee9270d",
"versionType": "git"
},
{
"status": "affected",
"version": "ed2b5a8e6b98d042b323afbe177a5dc618921b31",
"lessThan": "efe92ee7a111fe0f4d75f3ed6b7e3f86322279d5",
"versionType": "git"
},
{
"status": "affected",
"version": "ed2b5a8e6b98d042b323afbe177a5dc618921b31",
"lessThan": "e07dea3de508cd6950c937cec42de7603190e1ca",
"versionType": "git"
}
],
"programFiles": [
"drivers/phy/rockchip/phy-rockchip-inno-usb2.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.162",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.122",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.67",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.7",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/phy/rockchip/phy-rockchip-inno-usb2.c"
],
"defaultStatus": "affected"
}
]
},
{
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"affectedData": [
{
"vendor": "Siemens",
"product": "RUGGEDCOM RST2428P",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V4.0",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-01-31T12:16:06.313",
"references": [
{
"url": "https://git.kernel.org/stable/c/027d42b97e6eb827c3438ebc09bab7efaee9270d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b97b2c9808c9a97e0ce30216fa12096d8b0eaa75",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e07dea3de508cd6950c937cec42de7603190e1ca",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ebae26dd15140b840cf65be5e1c0daee949ba70b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/efe92ee7a111fe0f4d75f3ed6b7e3f86322279d5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html",
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: rockchip: inno-usb2: Fix a double free bug in rockchip_usb2phy_probe()\n\nThe for_each_available_child_of_node() calls of_node_put() to\nrelease child_np in each success loop. After breaking from the\nloop with the child_np has been released, the code will jump to\nthe put_child label and will call the of_node_put() again if the\ndevm_request_threaded_irq() fails. These cause a double free bug.\n\nFix by returning directly to avoid the duplicate of_node_put()."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nphy: rockchip: inno-usb2: Corrección de un error de doble liberación en rockchip_usb2phy_probe()\n\nLa función for_each_available_child_of_node() llama a of_node_put() para liberar child_np en cada bucle exitoso. Después de salir del bucle, una vez que child_np ha sido liberado, el código saltará a la etiqueta put_child y llamará a of_node_put() de nuevo si devm_request_threaded_irq() falla. Esto causa un error de doble liberación.\n\nSe corrige regresando directamente para evitar la llamada duplicada a of_node_put()."
}
],
"lastModified": "2026-06-17T10:20:44.543",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}