Review reviewHigh

CVE-2026-63906

Linux

In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Fix use-after-free in omap2430_probe() In omap2430_probe(), of_node_put(np) is called prematurely before the last access to np, leading to a use-after-free if the node's reference count drops to zero. Move the of_node_put() calls after the last use of np in both the success and error paths.

CVSS
8.4
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 8.4

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Fix use-after-free in omap2430_probe() In omap2430_probe(), of_node_put(np) is called prematurely before the last access to np, leading to a use-after-free if the node's reference count drops to zero. Move the of_node_put() calls after the last use of np in both the success and error paths.

Affected product and versions

Product
Linux
Affected versions
>= 22b60658a90260e3fbd57824e3afe5682c6afcf5 < 632fd888fe33083927e29ef651ac1aba345edd9e, >= ffbe2feac59b37c8dc536727552b4f375e1b9aec < b987f380620b38c84f054d5ff5c05861a7c2203b, >= ffbe2feac59b37c8dc536727552b4f375e1b9aec < 27e62532228dc42367bb43ebbcd7bf49d8db2b0d, >= ffbe2feac59b37c8dc536727552b4f375e1b9aec < 69f9f2b30af03d9b6e83f78fb0f734b6066d4678, >= ffbe2feac59b37c8dc536727552b4f375e1b9aec < d53e4c41331f57b9fd78cbf3e480c6ce20aea07b, >= ffbe2feac59b37c8dc536727552b4f375e1b9aec < e194ce048f5a6c549b3a23a8c568c6470f40f772, >= fed43efc00ba6ac8c6b95828cd5acfa3d45eca4d, >= 6.1.2 < 6.1.176, >= 6.0.16 < 6.1, >= 6.2
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2026-63906 — Linux | SECUFOCUS NOW