Use-after-free in Linux kernel - CVE-2026-63831
Published: July 20, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service or corrupt data.
The vulnerability exists due to use-after-free in the mac802154 llsec crypto processing in net/mac802154/llsec.c when performing in-place cryptographic transformations on shared skb data. A local user can trigger concurrent 802.15.4 traffic with security enabled to cause a denial of service or corrupt data.
The issue can affect both RX and TX paths when skb data buffers are shared across clones.
Affected software
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Ubuntu
kernel-rt (Red Hat package)
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-63831
kernel-rt (Red Hat package) - update to 4.18.0-553.167.1.rt7.508.el8_10
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/3a2b378b3a9ca75d3518d879148d2ad25b5714a9
- https://git.kernel.org/stable/c/7a831bcd0486788283ef35e396d4282ee01bb0d5
- https://git.kernel.org/stable/c/84a04eb5b210643bd67aab81ff805d32f62aa865
- https://git.kernel.org/stable/c/86d531337ea1ba02d9f2bc830d07c683d9bfaade
- https://git.kernel.org/stable/c/993fd674fe85d114e6a8d3963033d4fbbc2170a8
- https://git.kernel.org/stable/c/bd968bdd568beacfdf98ec537a87527e85f1d0cf
- https://git.kernel.org/stable/c/e28e7fd34c449028325322a3f5127b92594b7396
- https://git.kernel.org/stable/c/ff976ef7c39199ebff33c18034636595016db9f0