Use-after-free in Linux kernel - CVE-2026-53062
Published: June 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the dm-cache smq policy invalidate_mapping operation when handling concurrent writes in passthrough mode. A local user can trigger concurrent cache block invalidations to cause a denial of service.
The issue occurs when the cache is operating in passthrough mode and multiple workers invalidate cache blocks simultaneously.
How to mitigate CVE-2026-53062
Sources
- https://git.kernel.org/stable/c/1b2bec4a7dcf5f00b7a1cbeeec8997841d783513
- https://git.kernel.org/stable/c/2b62d0611c9af14a16bddf22df2612b4f40eb5a1
- https://git.kernel.org/stable/c/2d1f7b65f5deedd2e6b09fdc6ea27f8375f24b45
- https://git.kernel.org/stable/c/4991b5a08751e2e82488fb93ae08849b6aea10d9
- https://git.kernel.org/stable/c/93627a29d4b66d4a2def938dfb8610cc80ae454b
- https://git.kernel.org/stable/c/9a5fdfb9e57ec3a8ad2b8fce5e5ffa42d53b130e
- https://git.kernel.org/stable/c/ac5ee99443891bdb161f5539606a66a1b5e72542
- https://git.kernel.org/stable/c/c348ae47d8e65f06429fa41adce9ad986b696766