---
cve: "CVE-2026-53156"
severity: "LOW"
cvss: 3.1
epss: "13%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-06-25 09:16:32"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T09:26:04+02:00"
---

# CVE-2026-53156

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

nvmem: core: fix use-after-free bugs in error paths

Fix several instances of error paths in which we call
__nvmem_device_put() - which may end up freeing the underlying memory
and other resources - and then keep on using the nvmem structure. Always
put the reference to the nvmem device as the last step before returning
the error code.

## Patch verfügbar (OSV)

- Kernel ≥ 6.12.94
- Kernel ≥ 6.18.36
- Kernel ≥ 7.0.13

## Referenzen

- <https://git.kernel.org/stable/c/e0d38bf47a72da2f02c9fa6f752cd66d977cd7f7>
- <https://git.kernel.org/stable/c/cb85ef5a227b3662b88f4d849a1aad43bfe7f5ae>
- <https://git.kernel.org/stable/c/40e2a459c0dd1333b2343831480a0ad80dc07614>
- <https://git.kernel.org/stable/c/5b6b6fc491899d583eaa75344e094796ae9b530b>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-53156) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
