CVE.RADIO
FREN

CVE-2026-53286

LinuxVulnerabilityCVSS 7.8Patched

In the Linux kernel, the following vulnerability has been resolved: idpf: fix double free and use-after-free in aux device error paths When auxiliary_device_add() fails in idpf_plug_vport_aux_dev() or idpf_plug_core_aux_dev(), the err_aux_dev_add label calls auxiliary_device_uninit() and falls through to err_aux_dev_init. The uninit call will trigger put_device(), which invokes the release callback (idpf_vport_adev_release / idpf_core_adev_release) that frees iadev. The fall-through then reads adev->id from the freed iadev for ida_free() and double-frees iadev with kfree(). Free the IDA slot and clear the back-pointer before uninit, while adev is still valid, then return immediately. Commit 65637c3a1811 ("idpf: fix UAF in RDMA core aux dev deinitialization") fixed the same use-after-free in the matching unplug path in this file but missed both probe error paths.

No public exploitation has been reported so far. A fixed version is available (see the table below).

Recommended action: Update to the fixed version listed for your distribution using the native package manager.

CVE-2026-53286 Linux Vulnerability

Severity metrics

CVSS 3.1 : 7.8 HIGH

Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh

Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected & fixed versions by distribution

Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.

DistributionPackageAffectedFixed versionStatus
SUSE:Linux Micro 6.2kernel-default-base-6.12.0-160000.36.1.160000.2.17fixed
openSUSE:Leap 16.0kernel-default-6.12.0-160000.36.1fixed
openSUSE:Leap 16.0kernel-default-base-6.12.0-160000.36.1.160000.2.17fixed

Sources

Published 2026-06-26 · updated 2026-07-25 · source: NVD