Answer in brief
CVE-2026-68461 records a Unknown severity vulnerability in device property: initialize the remaining fields of fwnode_handle in fwnode_init(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-68461 records a Unknown severity vulnerability in device property: initialize the remaining fields of fwnode_handle in fwnode_init(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=01bb86b380a306bd937c96da36f66429f3362137 <0198d579948322cda5178b9672d448375a32f947 || >=01bb86b380a306bd937c96da36f66429f3362137 <173b61c9276c7b3a5fbcc63ae7aafc897fee1e18 || >=01bb86b380a306bd937c96da36f66429f3362137 <f0b4e1cc8ad76baf49d898727eb52e91a4ef0544 || >=01bb86b380a306bd937c96da36f66429f3362137 <c8542b68ba6ef4f61072098893a3f5b71c569b6c || >=01bb86b380a306bd937c96da36f66429f3362137 <9c86a1f930bb2ddb85f867b4736716e82a4a4683 || >=01bb86b380a306bd937c96da36f66429f3362137 <c81e2af41de6a159837c7129a4fc444ac6e48046 || >=01bb86b380a306bd937c96da36f66429f3362137 <7eba000621fff223dd7bab484d48918c7c77a307 | 0198d579948322cda5178b9672d448375a32f947, 173b61c9276c7b3a5fbcc63ae7aafc897fee1e18, f0b4e1cc8ad76baf49d898727eb52e91a4ef0544, c8542b68ba6ef4f61072098893a3f5b71c569b6c, 9c86a1f930bb2ddb85f867b4736716e82a4a4683, c81e2af41de6a159837c7129a4fc444ac6e48046, 7eba000621fff223dd7bab484d48918c7c77a307 |
| Linux/Linuxgeneric | 5.11 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: device property: initialize the remaining fields of fwnode_handle in fwnode_init() If a firmware node is allocated on the stack (for instance: temporary software node whose life-time we control) or on the heap - but using a non-zeroing allocation function - and initialized using fwnode_init(), its secondary pointer will contain uninitialized memory which likely will be neither NULL nor IS_ERR() and so may end up being dereferenced (for example: in dev_to_swnode()). Set fwnode->secondary to NULL on initialization. While at it: initialize the remaining fields of struct fwnode_handle too just to be sure. [ Fix typo in commit message. - Danilo ]
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=01bb86b380a306bd937c96da36f66429f3362137 <0198d579948322cda5178b9672d448375a32f947 || >=01bb86b380a306bd937c96da36f66429f3362137 <173b61c9276c7b3a5fbcc63ae7aafc897fee1e18 || >=01bb86b380a306bd937c96da36f66429f3362137 <f0b4e1cc8ad76baf49d898727eb52e91a4ef0544 || >=01bb86b380a306bd937c96da36f66429f3362137 <c8542b68ba6ef4f61072098893a3f5b71c569b6c || >=01bb86b380a306bd937c96da36f66429f3362137 <9c86a1f930bb2ddb85f867b4736716e82a4a4683 || >=01bb86b380a306bd937c96da36f66429f3362137 <c81e2af41de6a159837c7129a4fc444ac6e48046 || >=01bb86b380a306bd937c96da36f66429f3362137 <7eba000621fff223dd7bab484d48918c7c77a307 | 0198d579948322cda5178b9672d448375a32f947, 173b61c9276c7b3a5fbcc63ae7aafc897fee1e18, f0b4e1cc8ad76baf49d898727eb52e91a4ef0544, c8542b68ba6ef4f61072098893a3f5b71c569b6c, 9c86a1f930bb2ddb85f867b4736716e82a4a4683, c81e2af41de6a159837c7129a4fc444ac6e48046, 7eba000621fff223dd7bab484d48918c7c77a307 |
| Linux/Linuxgeneric | 5.11 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: device property: initialize the remaining fields of fwnode_handle in fwnode_init() If a firmware node is allocated on the stack (for instance: temporary software node whose life-time we control) or on the heap - but using a non-zeroing allocation function - and initialized using fwnode_init(), its secondary pointer will contain uninitialized memory which likely will be neither NULL nor IS_ERR() and so may end up being dereferenced (for example: in dev_to_swnode()). Set fwnode->secondary to NULL on initialization. While at it: initialize the remaining fields of struct fwnode_handle too just to be sure. [ Fix typo in commit message. - Danilo ]
Quoted source text, attributed separately from HOL analysis.