Use-after-free in Linux kernel - CVE-2026-53189
Published: June 26, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in __split_huge_pmd_locked() when splitting a huge PMD mapping. A local user can trigger the affected memory-management path to cause a denial of service.
The issue occurs because file/shmem RSS accounting may access freed folio state after the last folio reference is dropped.
Affected software
Red Hat Enterprise Linux for Real Time for NFV
Anolis OS
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
IBM DataPower Gateway
kernel-rt (Red Hat package)
kernel-doc
kernel-abi-stablelists
python3-perf
perf
kernel-tools-libs-devel
kernel-tools-libs
kernel-tools
kernel-modules-extra
kernel-modules
kernel-headers
kernel-devel
kernel-debug-modules-extra
kernel-debug-modules
kernel-debug-devel
kernel-debug-core
kernel-debug
kernel-cross-headers
kernel-core
kernel
bpftool
kernel (Red Hat package)
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-7.0 (Ubuntu package)
linux-raspi (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-53189
IBM DataPower Gateway - update to 11.0.0.3
kernel-rt (Red Hat package) - update to 4.18.0-553.157.1.rt7.498.el8_10
kernel-doc - update to 4.18.0-553.157.1.0.1
kernel-abi-stablelists - update to 4.18.0-553.157.1.0.1
python3-perf - update to 4.18.0-553.157.1.0.1
perf - update to 4.18.0-553.157.1.0.1
kernel-tools-libs-devel - update to 4.18.0-553.157.1.0.1
kernel-tools-libs - update to 4.18.0-553.157.1.0.1
kernel-tools - update to 4.18.0-553.157.1.0.1
kernel-modules-extra - update to 4.18.0-553.157.1.0.1
kernel-modules - update to 4.18.0-553.157.1.0.1
kernel-headers - update to 4.18.0-553.157.1.0.1
kernel-devel - update to 4.18.0-553.157.1.0.1
kernel-debug-modules-extra - update to 4.18.0-553.157.1.0.1
kernel-debug-modules - update to 4.18.0-553.157.1.0.1
kernel-debug-devel - update to 4.18.0-553.157.1.0.1
kernel-debug-core - update to 4.18.0-553.157.1.0.1
kernel-debug - update to 4.18.0-553.157.1.0.1
kernel-cross-headers - update to 4.18.0-553.157.1.0.1
kernel-core - update to 4.18.0-553.157.1.0.1
kernel - update to 4.18.0-553.157.1.0.1
bpftool - update to 4.18.0-553.157.1.0.1
kernel (Red Hat package) - update to 6.12.0-211.50.1.el10_2
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1011.11, 7.0.0-1014.14
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux-ibm (Ubuntu package) - update to 7.0.0-1013.13
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
linux-nvidia (Ubuntu package) - update to 7.0.0-1018.18
linux-nvidia-7.0 (Ubuntu package) - update to 7.0.0-1018.18~24.04.1
linux-raspi (Ubuntu package) - update to 7.0.0-1019.19
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2018.18
External References
- https://git.kernel.org/stable/c/108963978a681c0c468d279cac2b930c27672877
- https://git.kernel.org/stable/c/459771c9cf30f378bdbd30fc65d17f7eb931bb59
- https://git.kernel.org/stable/c/5f5b604e1e6bde4e889199168ee80fe8306d06ad
- https://git.kernel.org/stable/c/6c29a8ba084e89499ca77b947e07ae817f9c16ce
- https://git.kernel.org/stable/c/84b3212b166b446faea27ebebb7161405ffceef9
- https://git.kernel.org/stable/c/8d878059924f12c1bc24556a92ec56add74de3c8
- https://git.kernel.org/stable/c/ae9d4caf6f133e884cf5fcda4982c493b35e5194
- https://git.kernel.org/stable/c/ed5b030931292c94133437ac5e5ff580e498eabd
Related Security Bulletins
- Use-after-free in Linux kernel mm
- Red Hat Enterprise Linux 8 update for kernel-rt
- Red Hat Enterprise Linux 10 update for kernel
- Anolis OS update for kernel:4.18
- Ubuntu update for linux-oem-7.0
- Ubuntu update for linux
- Ubuntu update for linux-gcp-7.0
- Multiple vulnerabilities in IBM DataPower Gateway
- Ubuntu update for linux-oracle-7.0
- Ubuntu update for linux-azure
- Ubuntu update for linux-azure-7.0
- Ubuntu update for linux-nvidia
- Ubuntu update for linux-nvidia-bos
- Ubuntu update for linux-ibm
- Ubuntu update for linux-raspi
- Ubuntu update for linux-nvidia-7.0