CVE-2026-53157: falha em Linux
net: phonet: free phonet_device after RCU grace period
Publicada em · Atualizada em
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 0.1%
probabilidade de exploração
0.1%top 98% das CVEs
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
net: phonet: free phonet_device after RCU grace period
phonet_device_destroy() removes a phonet_device from the per-net device
list with list_del_rcu(), but frees it immediately. RCU readers walking
the same list can still hold a pointer to the object after it has been
removed, leading to a slab-use-after-free.
Use kfree_rcu(), matching the lifetime rule already used by
phonet_address_del() for the same object type.
Produtos afetados
Linux · LinuxCVEs relacionadas — Linux
No mesmo produto, das mais perigosas para as menos.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
Referências
https://git.kernel.org/stable/c/09c9b92c2010481160245244ea8fa1d06d5d4ae0https://git.kernel.org/stable/c/2ec8011cce0cd0fc7a5068585d867fc08d508578https://git.kernel.org/stable/c/52b8f5ef82c886f7cd24617915e4b1579ddfd001https://git.kernel.org/stable/c/6cd7067d6e4b0b2033ba2f918ecbd54dc2af3763https://git.kernel.org/stable/c/71de0177b28da751f407581a4515cf4d762f6296https://git.kernel.org/stable/c/bd2ab4d800fc26814d89328d87b5f97ef6aa906ahttps://git.kernel.org/stable/c/bff309ea51f1395c1ef8be8b75ce62d28a319113https://git.kernel.org/stable/c/d59794337ea496042288c7c68356d9b9ca7f46a9