CVE-2026-97972 PUBLISHED

net: macb: put the "mdio" child node reference on success

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

net: macb: put the "mdio" child node reference on success

macb_mii_init() holds the reference returned by of_get_child_by_name() for macb_mdiobus_register() and drops it only on the error paths, so every successful probe leaks a node reference. On a CM5, overlay removal after four bind cycles reports

OF: ERROR: memory leak, expected refcount 1 instead of 5

Drop the reference after registration, where __mdiobus_register() has already taken its own for the lifetime of the bus.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 8a6631f1cece09047fa44608d21d520ca65ce7d8 to 5fba30080d298edb742396073372385c961578d3 (excl.)
  • affected from 8a6631f1cece09047fa44608d21d520ca65ce7d8 to 7d60dc7ff85b73a2119d582ca2d4456b30960380 (excl.)
  • affected from 8a6631f1cece09047fa44608d21d520ca65ce7d8 to 382a373d9ea7a6ac4de9c022385b6217f65ae3cc (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.13 is affected
  • unaffected from 0 to 6.13 (excl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc3 to * (incl.)

References