CVE-2026-64249

Source
https://cve.org/CVERecord?id=CVE-2026-64249
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64249.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64249
Downstream
Related
Published
2026-07-24T15:31:16.458Z
Modified
2026-08-18T03:30:59.115554709Z
Summary
fpga: region: fix use-after-free in child_regions_with_firmware()
Details

In the Linux kernel, the following vulnerability has been resolved:

fpga: region: fix use-after-free in childregionswith_firmware()

Move ofnodeput(childregion) after the error print to avoid accessing freed memory when prerr() references child_region.

[ Yilun: Fix the Fixes tag ]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64249.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0fa20cdfcc1f68847cdfc47824476301eedc8297
Fixed
e918942bcc5355ad5b44ba557935dffc0727b0eb
Fixed
866184fc7ae42a0070f1141ae8c5dca7c24a59e2
Fixed
070b0ce947b18fa3dec0729695147f7e19599649
Fixed
fbaf509ad7cb2f7dafe73ca20c956104cfcc9d68
Fixed
e79afcb0a66d2b3c33e510eade902537e656fc00
Fixed
369496d885b4cf6e8647cf4dc5cf3ac68fdf37a1
Fixed
5e098e40e8bac43ed58645c10d5fad781966efe4
Fixed
54f3c5643ec523a04b6ec0e7c19eb10f5ebebdd3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64249.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
5.10.260
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.211
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.177
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.144
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.95
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.38
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64249.json"