SB20260720303 - Use-after-free in Linux kernel iio buffer driver
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-63930)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in iio_hw_consumer_alloc() when cleaning up buffers in the error path. A local user can trigger the vulnerable cleanup path to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/29783e6b6ec0b7152a15e53a063f17537e81177d
- https://git.kernel.org/stable/c/2ff615fc455acda5425c4900160cbe11cfea4449
- https://git.kernel.org/stable/c/6f5ed4f2c7c83f33344e0ba179f72a12e5dad4a4
- https://git.kernel.org/stable/c/9319c94f63ed10723afd738d79f5617daba87cc8
- https://git.kernel.org/stable/c/a3763ae33476328cf8d661742deb9daec78eac96
- https://git.kernel.org/stable/c/b71893c57730809c222766e5718bb33610f11963
- https://git.kernel.org/stable/c/d2759d49860b9a39b5cde2fb88e4b822ddf5f58f
- https://git.kernel.org/stable/c/e965627f0d442bfcae3f496c90cb653fb0917a61