CVE-2026-63906
usb: musb: omap2430: Fix use-after-free in omap2430_probe()
Description
In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Fix use-after-free in omap2430_probe() In omap2430_probe(), of_node_put(np) is called prematurely before the last access to np, leading to a use-after-free if the node's reference count drops to zero. Move the of_node_put() calls after the last use of np in both the success and error paths.
INFO
Published Date :
July 19, 2026, 4:17 p.m.
Last Modified :
July 27, 2026, 5:44 p.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Move of_node_put() after last access to np.
- Ensure np is not used after of_node_put().
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-63906.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-63906 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-63906
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-63906 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-63906 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jul. 20, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jul. 19, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '22b60658a90260e3fbd57824e3afe5682c6afcf5', 'lessThan': '632fd888fe33083927e29ef651ac1aba345edd9e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffbe2feac59b37c8dc536727552b4f375e1b9aec', 'lessThan': 'b987f380620b38c84f054d5ff5c05861a7c2203b', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffbe2feac59b37c8dc536727552b4f375e1b9aec', 'lessThan': '27e62532228dc42367bb43ebbcd7bf49d8db2b0d', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffbe2feac59b37c8dc536727552b4f375e1b9aec', 'lessThan': '69f9f2b30af03d9b6e83f78fb0f734b6066d4678', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffbe2feac59b37c8dc536727552b4f375e1b9aec', 'lessThan': 'd53e4c41331f57b9fd78cbf3e480c6ce20aea07b', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffbe2feac59b37c8dc536727552b4f375e1b9aec', 'lessThan': 'e194ce048f5a6c549b3a23a8c568c6470f40f772', 'versionType': 'git'}, {'status': 'affected', 'version': 'fed43efc00ba6ac8c6b95828cd5acfa3d45eca4d', 'versionType': 'git'}, {'status': 'affected', 'version': '6.1.2', 'lessThan': '6.1.176', 'versionType': 'semver'}, {'status': 'affected', 'version': '6.0.16', 'lessThan': '6.1', 'versionType': 'semver'}], 'programFiles': ['drivers/usb/musb/omap2430.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.2'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.2', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.176', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.143', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.93', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.35', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.12', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/usb/musb/omap2430.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Fix use-after-free in omap2430_probe() In omap2430_probe(), of_node_put(np) is called prematurely before the last access to np, leading to a use-after-free if the node's reference count drops to zero. Move the of_node_put() calls after the last use of np in both the success and error paths. Added Reference https://git.kernel.org/stable/c/27e62532228dc42367bb43ebbcd7bf49d8db2b0d Added Reference https://git.kernel.org/stable/c/632fd888fe33083927e29ef651ac1aba345edd9e Added Reference https://git.kernel.org/stable/c/69f9f2b30af03d9b6e83f78fb0f734b6066d4678 Added Reference https://git.kernel.org/stable/c/b987f380620b38c84f054d5ff5c05861a7c2203b Added Reference https://git.kernel.org/stable/c/d53e4c41331f57b9fd78cbf3e480c6ce20aea07b Added Reference https://git.kernel.org/stable/c/e194ce048f5a6c549b3a23a8c568c6470f40f772