High severity7.8NVD Advisory· Published Aug 16, 2025· Updated Jul 30, 2026
CVE-2025-38536
CVE-2025-38536
Description
In the Linux kernel, the following vulnerability has been resolved:
net: airoha: fix potential use-after-free in airoha_npu_get()
np->name was being used after calling of_node_put(np), which releases the node and can lead to a use-after-free bug. Previously, of_node_put(np) was called unconditionally after of_find_device_by_node(np), which could result in a use-after-free if pdev is NULL.
This patch moves of_node_put(np) after the error check to ensure the node is only released after both the error and success cases are handled appropriately, preventing potential resource issues.
Affected products
10cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.15,<6.15.8
- cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.16:rc6:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 6.15
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.