Use-after-free in Linux kernel - CVE-2026-53189

 

Use-after-free in Linux kernel - CVE-2026-53189

Published: June 26, 2026


Vulnerability identifier: #VU135594
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53189
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in __split_huge_pmd_locked() when splitting a huge PMD mapping. A local user can trigger the affected memory-management path to cause a denial of service.

The issue occurs because file/shmem RSS accounting may access freed folio state after the last folio reference is dropped.


Affected software

Linux kernel
Red Hat Enterprise Linux for Real Time for NFV
Anolis OS
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
IBM DataPower Gateway
kernel-rt (Red Hat package)
kernel-doc
kernel-abi-stablelists
python3-perf
perf
kernel-tools-libs-devel
kernel-tools-libs
kernel-tools
kernel-modules-extra
kernel-modules
kernel-headers
kernel-devel
kernel-debug-modules-extra
kernel-debug-modules
kernel-debug-devel
kernel-debug-core
kernel-debug
kernel-cross-headers
kernel-core
kernel
bpftool
kernel (Red Hat package)
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-7.0 (Ubuntu package)
linux-raspi (Ubuntu package)
linux-nvidia-bos (Ubuntu package)

How to mitigate CVE-2026-53189

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
IBM DataPower Gateway - update to 11.0.0.3
kernel-rt (Red Hat package) - update to 4.18.0-553.157.1.rt7.498.el8_10
kernel-doc - update to 4.18.0-553.157.1.0.1
kernel-abi-stablelists - update to 4.18.0-553.157.1.0.1
python3-perf - update to 4.18.0-553.157.1.0.1
perf - update to 4.18.0-553.157.1.0.1
kernel-tools-libs-devel - update to 4.18.0-553.157.1.0.1
kernel-tools-libs - update to 4.18.0-553.157.1.0.1
kernel-tools - update to 4.18.0-553.157.1.0.1
kernel-modules-extra - update to 4.18.0-553.157.1.0.1
kernel-modules - update to 4.18.0-553.157.1.0.1
kernel-headers - update to 4.18.0-553.157.1.0.1
kernel-devel - update to 4.18.0-553.157.1.0.1
kernel-debug-modules-extra - update to 4.18.0-553.157.1.0.1
kernel-debug-modules - update to 4.18.0-553.157.1.0.1
kernel-debug-devel - update to 4.18.0-553.157.1.0.1
kernel-debug-core - update to 4.18.0-553.157.1.0.1
kernel-debug - update to 4.18.0-553.157.1.0.1
kernel-cross-headers - update to 4.18.0-553.157.1.0.1
kernel-core - update to 4.18.0-553.157.1.0.1
kernel - update to 4.18.0-553.157.1.0.1
bpftool - update to 4.18.0-553.157.1.0.1
kernel (Red Hat package) - update to 6.12.0-211.50.1.el10_2
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1011.11, 7.0.0-1014.14
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux-ibm (Ubuntu package) - update to 7.0.0-1013.13
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
linux-nvidia (Ubuntu package) - update to 7.0.0-1018.18
linux-nvidia-7.0 (Ubuntu package) - update to 7.0.0-1018.18~24.04.1
linux-raspi (Ubuntu package) - update to 7.0.0-1019.19
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2018.18

External References

Related Security Bulletins