Use-after-free in Linux kernel - CVE-2026-46267
Published: June 4, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in llc_shdlc_deinit and SHDLC state machine work handling when tearing down the SHDLC context while timers or queued work remain active. A local user can trigger concurrent teardown and work execution to cause a denial of service.
The issue involves shutdown races where timer callbacks can schedule sm_work that accesses SHDLC state and skb queues after the context is freed.
How to mitigate CVE-2026-46267
Sources
- https://git.kernel.org/stable/c/1cb97b1225450af3f7b728777929ba50c6a58ced
- https://git.kernel.org/stable/c/276820278e9717cc7d4bb32381892dd3ddf418d4
- https://git.kernel.org/stable/c/77eef9f2eef045c3c37a3df82d3e661afb866b98
- https://git.kernel.org/stable/c/a24a676329d40481b2331bfa1418a679577dfd3a
- https://git.kernel.org/stable/c/c60f41022eaad2a1dafecd3ae6f249a3bd6d4b6e
- https://git.kernel.org/stable/c/c9efde1e537baed7648a94022b43836a348a074f
- https://git.kernel.org/stable/c/cf70cedce327833296ebe6043364d1e44b76a2ab