Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-89744

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Sep 11, 2026
Vendor unknown

Description

In the Linux kernel, the following vulnerability has been resolved: device property: fix infinite loop in fwnode_for_each_child_node() When iterate over children of a fwnode that has a secondary fwnode, fwnode_get_next_child_node() can enter an infinite loop if the secondary fwnode has more than one child. Parent Child (Primary fwnode) FWa: {FWa1, FWa2, FWa3} (Secondary fwnode) FWb: {FWb1, FWb2} In this case: โ”Œโ”€> fwnode_get_next_child_node(FWa, FWa1) โ”‚ - fwnode_call_ptr_op(FWa, get_next_child_node, FWa1) returns FWa2 โ”‚ โ”‚ ... โ”‚ โ”‚ fwnode_get_next_child_node(FWa, FWa3) โ”‚ - fwnode_call_ptr_op(FWa, get_next_child_node, FWa3) returns NULL โ”‚ - fwnode_call_ptr_op(FWb, get_next_child_node, FWa3) returns FWb1 โ”‚ โ”‚ fwnode_get_next_child_node(FWa, FWb1) โ”‚ - fwnode_call_ptr_op(FWa, get_next_child_node, FWb1) returns FWa1 โ””โ”€โ”€โ”€โ”€โ”˜ This cause fwnode_for_each_child_node() to loop indefinitely, reapeatedly output {FWa1, FWa2, FWa3, FWb1, FWa1, ...}. The root cause is that when the current child (FWb1) belongs to the secondary fwnode, calling get_next_child_node() on the parimary fwnode incorrectly returns the first child (FWa1) again instead of NULL. Fix this by dynamically checking the parent fwnode of the current child before calling get_next_child_node(). This approach follows the pattern established in commit b5b41ab6b0c1 ("device property: Check fwnode->secondary in fwnode_graph_get_next_endpoint()").

References