CVE-2026-53160
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-416
Utilización después de liberación
Fecha de publicación:
25/06/2026
Última modificación:
06/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
misc: fastrpc: fix use-after-free race in fastrpc_map_create<br />
<br />
fastrpc_map_lookup returns a raw pointer after releasing fl->lock. The<br />
caller fastrpc_map_create then calls fastrpc_map_get (kref_get_unless_zero)<br />
on this unprotected pointer. A concurrent MEM_UNMAP can free the map<br />
between the lock release and the kref operation, resulting in a<br />
use-after-free on the freed slab object.<br />
<br />
Restore the take_ref parameter to fastrpc_map_lookup so the reference<br />
is acquired atomically under fl->lock before the pointer is exposed to<br />
the caller.
Impacto
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.1.156 (incluyendo) | 6.1.176 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6.112 (incluyendo) | 6.6.143 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.12.53 (incluyendo) | 6.12.94 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.17.3 (incluyendo) | 6.18.36 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.13 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/07ebe87915d8accdaba20c4f88c5ae430fe62fbb
- https://git.kernel.org/stable/c/0a3b87293fbd34fda651e6aead9964f84b893962
- https://git.kernel.org/stable/c/5b0166112019d1dce30b976ab28fd67f7f0be532
- https://git.kernel.org/stable/c/8b080c89183196fd3e49212f2a1a1c4a29335b9c
- https://git.kernel.org/stable/c/992f121796b7ca83a5a8b93da24e971363206218
- https://git.kernel.org/stable/c/f20f6512ecb75c816e0debf4551a138f098615c4



