CVE-2026-53157 | In the Linux kernel, the following vulnerability has been resolved: net: phonet: free phonet_device after RCU grace period phonet_device_destroy() removes a phonet_device from the per-net device list with list_del_rcu(), but frees it immediately. RCU readers walking the same list can still hold a pointer to the object after it has been removed, leading to a slab-use-after-free. Use kfree_rcu(), matching the lifetime rule already used by phonet_address_del(
In the Linux kernel, the following vulnerability has been resolved:
net: phonet: free phonet_device after RCU grace period
phonet_device_destroy() removes a phonet_device from the per-net device
list with list_del_rcu(), but frees it immediately. RCU readers walking
the same list can still hold a pointer to the object after it has been
removed, leading to a slab-use-after-free.
Use kfree_rcu(), matching the lifetime rule already used by
phonet_address_del() for the same object type.
- 🔗 git.kernel.org/stable/c/d59794337ea496042288c7c68356d9b9…
- 🔗 git.kernel.org/stable/c/6cd7067d6e4b0b2033ba2f918ecbd54d…
- 🔗 git.kernel.org/stable/c/2ec8011cce0cd0fc7a5068585d867fc0…
- 🔗 git.kernel.org/stable/c/09c9b92c2010481160245244ea8fa1d0…
- 🔗 git.kernel.org/stable/c/bd2ab4d800fc26814d89328d87b5f97e…
- 🔗 git.kernel.org/stable/c/52b8f5ef82c886f7cd24617915e4b157…
- 🔗 git.kernel.org/stable/c/bff309ea51f1395c1ef8be8b75ce62d2…
- 🔗 git.kernel.org/stable/c/71de0177b28da751f407581a4515cf4d…
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-06 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-53157 | In the Linux kernel, the following vulnerability has been resolved: net: phonet: free phonet_device after RCU grace period phonet_device_destroy() removes a phonet_device from the per-net device list with list_del_rcu(), but frees it immediately. RCU readers walking the same list can still hold a pointer to the object after it has been removed, leading to a slab-use-after-free. Use kfree_rcu(), matching the lifetime rule already used by phonet_address_del(
In the Linux kernel, the following vulnerability has been resolved: net: phonet: free phonet_device after RCU grace period phonet_device_destroy() removes a phonet_device from the per-net device list with list_del_rcu(), but frees it imme