CVE-2026-52982 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit() when accessing skb->len for tx statistics after usb_submit_urb() has been called: BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f/0x760 drivers/net/usb/rtl8150.c:712 Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226 The URB completion handler write_bulk_callback() frees the skb via dev_kfree_skb_irq(dev->tx_skb). The URB may complete on another CPU in softirq context before usb_submit_urb() returns in the submitter, so by the time the submitter reads skb->len the skb has already been queued to the per-CPU completion_queue and freed by net_tx_action(): CPU A (xmit) CPU B (USB completion softirq) ------------ ------------------------------ dev->tx_skb = skb; usb_submit_urb() --+ |-------> write_bulk_callback() | dev_kfree_skb_irq(dev->tx_skb) | net_tx_action() | napi_skb_cache_put() <-- free netdev->stats.tx_bytes | += skb->len; <-- UAF read Fix it by caching skb->len before submitting the URB and using the cached value when updating the tx_bytes counter. The pre-existing tx_bytes semantics are preserved: the counter tracks the original frame length (skb->len), not the ETH_ZLEN/USB-alignment padded "count" value that is handed to the device. Changing that would be a user-visible accounting change and is out of scope for this UAF fix.
A use-after-free vulnerability has been identified in the Linux kernel's RTL8150 USB driver. This issue arises in the 'rtl8150_start_xmit' function, where the transmission statistics are updated after the USB request has been submitted. The problem occurs because the completion handler for the USB request frees the socket buffer before the transmission statistics are updated, leading to a use-after-free condition. The vulnerability was reported by syzbot and is addressed by caching the length of the socket buffer before submitting the USB request, ensuring that the correct value is used when updating the transmission statistics.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/23f0e34c64acba15cad4d23e50f41f533da195fa | kernel.org | Patch |
| https://git.kernel.org/stable/c/24831b0b2ada9fef18d1f486b7b7c444ee5ba637 | kernel.org | Patch |
| https://git.kernel.org/stable/c/30cf9829d09ca958279c937af8e35495cd2f1e09 | kernel.org | Patch |
| https://git.kernel.org/stable/c/423b5b86e14e190f6e3161eb5f2ea5f908295ba7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4dd7eb94f79486b77ca6b4c8676aedbc465dc802 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5af290c86fa81ddbc86a08d54229af5daa40c6a4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5db090ca07b28a63fb1499690cf19a3f3adafacb | kernel.org | Patch |
| https://git.kernel.org/stable/c/6999d70e0eda39af029fa1891c48f0a8832b09d5 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.12.1, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.141 >= 6.7, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 2.6.12 - 2.6.12 rc2 2.6.12 rc3 2.6.12 rc4 2.6.12 rc5 7.1 rc1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jun 28, 2026 | CVE Modified | kernel.org |
| Jun 24, 2026 | New CVE Received | kernel.org |