SB20260815227 - Use-after-free in Linux kernel staging nvec driver
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-72489)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in nvec_rx_completed() when handling an incomplete RX transfer. A local user can trigger an incomplete RX transfer to execute arbitrary code.
The freed message slot may be reallocated by a concurrent call to nvec_msg_alloc() before the code reads the message type byte.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/08626fcfe12308ca3f8b22c538ba7dee0b2dce7a
- https://git.kernel.org/stable/c/26813881181deb3a32fbb59eadb2599cbe8423f6
- https://git.kernel.org/stable/c/5de04caa46b635e180cecbd164e333eca535db94
- https://git.kernel.org/stable/c/6b2ea886ebdae44a2394029844a4e78f58e1587d
- https://git.kernel.org/stable/c/9f7fe4165a1f1014bdadc8e744c0fd3c2d8c0b89
- https://git.kernel.org/stable/c/a37625c7b688fcf68a54263528eccbabfd7fa17a
- https://git.kernel.org/stable/c/bb3d592c7d6c4ec8ac6640c690ca13298e7e8e90
- https://git.kernel.org/stable/c/f19a5bc059051143c489dd6f79a0f9c3bfd13aea