-

CVE-2026-93134

printk: Fix possible console use-after-free

In the Linux kernel, the following vulnerability has been resolved:

printk: Fix possible console use-after-free

When emitting a record via legacy printing, it is possible that a handover
to another legacy printing context occurs. When a context has performed a
handover, the console SRCU read lock is released and the pointer to the
console struct might now be invalid. Therefore, after calling
nbcon_legacy_emit_next_record() or console_emit_next_record(), it is
necessary to check if a handover occurred _before_ further @con usage.

Sashiko pointed out that console_flush_one_record() was not doing this.

In console_flush_one_record(), after emitting a record, move the further
usage of @con after the handover check.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version c158834b223fbfab3a14855ac203b8d9cddbbefd
Version < f0104a7b730de32eefb3d4a27279592b5504ad59
Status affected
Version c158834b223fbfab3a14855ac203b8d9cddbbefd
Version < fbf9bb81b21537ede387a31cc586f1d2ce66a74e
Status affected
Version c158834b223fbfab3a14855ac203b8d9cddbbefd
Version < 8f194dee0c0d1223255bae1429e1939882f540fc
Status affected
Version c158834b223fbfab3a14855ac203b8d9cddbbefd
Version < 36630cafbeede0b64c370edb2f7b4094327ee1e0
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.12
Status affected
Version 0
Version < 6.12
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f0104a7b730de32eefb3d4a27279592b5504ad59
https://git.kernel.org/stable/c/fbf9bb81b21537ede387a31cc586f1d2ce66a74e
https://git.kernel.org/stable/c/8f194dee0c0d1223255bae1429e1939882f540fc
https://git.kernel.org/stable/c/36630cafbeede0b64c370edb2f7b4094327ee1e0