Use-after-free in Linux kernel - CVE-2026-53189

 

Use-after-free in Linux kernel - CVE-2026-53189

Published: June 26, 2026


Vulnerability identifier: #VU135594
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53189
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in __split_huge_pmd_locked() when splitting a huge PMD mapping. A local user can trigger the affected memory-management path to cause a denial of service.

The issue occurs because file/shmem RSS accounting may access freed folio state after the last folio reference is dropped.


Affected software

Linux kernel
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
kernel-rt (Red Hat package)

How to mitigate CVE-2026-53189

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
kernel-rt (Red Hat package) - update to 4.18.0-553.157.1.rt7.498.el8_10

External References

Related Security Bulletins