8.4
CVE-2026-72489
- EPSS 0.15%
- Veröffentlicht 15.08.2026 05:57:24
- Zuletzt bearbeitet 17.08.2026 06:19:17
- Erkennungen
staging: nvec: fix use-after-free in nvec_rx_completed()
In the Linux kernel, the following vulnerability has been resolved: staging: nvec: fix use-after-free in nvec_rx_completed() In nvec_rx_completed(), when an incomplete RX transfer is detected, nvec_msg_free() is called to return the message back to the pool by clearing its 'used' atomic flag. Immediately after this, the code accesses nvec->rx->data[0] to check the message type. Since nvec_msg_free() marks the pool slot as available via atomic_set(), any concurrent or subsequent call to nvec_msg_alloc() could claim that same slot and overwrite its data[] array. Reading nvec->rx->data[0] after freeing the message is therefore a use-after-free. Fix this by saving the message type byte before calling nvec_msg_free(), then using the saved value for the battery quirk check.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
d6bdcf2e1019351cbc176e963b7756766bdd8721
Version <
6b2ea886ebdae44a2394029844a4e78f58e1587d
Status
affected
Version
d6bdcf2e1019351cbc176e963b7756766bdd8721
Version <
a37625c7b688fcf68a54263528eccbabfd7fa17a
Status
affected
Version
d6bdcf2e1019351cbc176e963b7756766bdd8721
Version <
9f7fe4165a1f1014bdadc8e744c0fd3c2d8c0b89
Status
affected
Version
d6bdcf2e1019351cbc176e963b7756766bdd8721
Version <
08626fcfe12308ca3f8b22c538ba7dee0b2dce7a
Status
affected
Version
d6bdcf2e1019351cbc176e963b7756766bdd8721
Version <
f19a5bc059051143c489dd6f79a0f9c3bfd13aea
Status
affected
Version
d6bdcf2e1019351cbc176e963b7756766bdd8721
Version <
bb3d592c7d6c4ec8ac6640c690ca13298e7e8e90
Status
affected
Version
d6bdcf2e1019351cbc176e963b7756766bdd8721
Version <
5de04caa46b635e180cecbd164e333eca535db94
Status
affected
Version
d6bdcf2e1019351cbc176e963b7756766bdd8721
Version <
26813881181deb3a32fbb59eadb2599cbe8423f6
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.2
Status
affected
Version
0
Version <
3.2
Status
unaffected
Version <=
5.10.*
Version
5.10.261
Status
unaffected
Version <=
5.15.*
Version
5.15.212
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.97
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.047 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/6b2ea886ebdae44a2394029844a4e78f58e1587d
https://git.kernel.org/stable/c/a37625c7b688fcf68a54263528eccbabfd7fa17a
https://git.kernel.org/stable/c/9f7fe4165a1f1014bdadc8e744c0fd3c2d8c0b89
https://git.kernel.org/stable/c/08626fcfe12308ca3f8b22c538ba7dee0b2dce7a
https://git.kernel.org/stable/c/f19a5bc059051143c489dd6f79a0f9c3bfd13aea
https://git.kernel.org/stable/c/bb3d592c7d6c4ec8ac6640c690ca13298e7e8e90
https://git.kernel.org/stable/c/5de04caa46b635e180cecbd164e333eca535db94
https://git.kernel.org/stable/c/26813881181deb3a32fbb59eadb2599cbe8423f6