Back

MEDIUM

of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails

Published Aug 15, 2026

Description

The global pointer 'reserved_mem' continues to reference the reserved_mem_array which lives in __initdata if alloc_reserved_mem_array() fails. of_reserved_mem_lookup() is exported for post-init use, that would dereference freed memory and trigger a use-after-free.

So reset reserved_mem_count to 0 when alloc_reserved_mem_array() fails.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Aug 15, 2026
Updated Aug 17, 2026
Reserved Aug 15, 2026

CISA Vulnrichment

No data

NVD

Status Received
Modified Aug 17, 2026

Red Hat

Severity Moderate
Public date Aug 15, 2026
Bugzilla 2516825

ENISA EUVD

Assigner Linux
Published Aug 15, 2026
Updated Aug 17, 2026

GitHub

No data