CVE-2026-53157 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net: phonet: free phonet_device after RCU grace period phonet_device_destroy() removes a phonet_device from the per-net device list with list_del_rcu(), but frees it immediately. RCU readers walking the same list can still hold a pointer to the object after it has been removed, leading to a slab-use-after-free. Use kfree_rcu(), matching the lifetime rule already used by phonet_address_del() for the same object type.
A use-after-free vulnerability has been identified in the Linux kernel's phonet subsystem. The issue arises in the 'phonet_device_destroy' function, which removes a 'phonet_device' from the per-net device list using 'list_del_rcu()' but immediately frees the device. This creates a race condition, as RCU readers traversing the list may still hold a pointer to the freed object, leading to a slab-use-after-free condition. The vulnerability affects the Linux kernel stable tree.
The vulnerability has been fixed by changing the memory deallocation from 'kfree()' to 'kfree_rcu()', which aligns with the proper lifetime management for RCU objects. Users should upgrade to the patched version of the Linux kernel available in the Linux kernel Git repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/09c9b92c2010481160245244ea8fa1d06d5d4ae0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/2ec8011cce0cd0fc7a5068585d867fc08d508578 | kernel.org | Patch |
| https://git.kernel.org/stable/c/52b8f5ef82c886f7cd24617915e4b1579ddfd001 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6cd7067d6e4b0b2033ba2f918ecbd54dc2af3763 | kernel.org | Patch |
| https://git.kernel.org/stable/c/71de0177b28da751f407581a4515cf4d762f6296 | kernel.org | Patch |
| https://git.kernel.org/stable/c/bd2ab4d800fc26814d89328d87b5f97ef6aa906a | kernel.org | Patch |
| https://git.kernel.org/stable/c/bff309ea51f1395c1ef8be8b75ce62d28a319113 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d59794337ea496042288c7c68356d9b9ca7f46a9 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.33, < 5.10.260 >= 5.11, < 5.15.211 >= 5.16, < 6.1.177 >= 6.2, < 6.6.144 >= 6.7, < 6.12.95 >= 6.13, < 6.18.36 >= 6.19, < 7.0.13 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 7.1 rc5 7.1 rc6 7.1 rc7 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | Initial Analysis | [email protected] |
| Jul 4, 2026 | CVE Modified | kernel.org |
| Jun 25, 2026 | New CVE Received | kernel.org |