CVE-2026-53247: net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
In the Linux kernel, the following vulnerability has been resolved:
Other sources
net: ethernet: mtkethsoc: Fix use-after-free in metadata dst teardown
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.143.1-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.1.13-1 - Configuration
Because skb_dst_set_noref() creates a non-refcounted pointer, ensure RCU read-side protection is used so that the dst is not freed until all RCU readers have completed.
Linux kernel (RCU/dst lifetime handling in mtk_eth_soc RX path) RCU read-side protection / dst lifetime = Ensure RCU read-side protection is in place so the dst remains valid until all RCU readers complete
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53247?
The severity of CVE-2026-53247 is rated at 43.
How do I fix CVE-2026-53247?
To fix CVE-2026-53247, update the Linux kernel to the latest version where the vulnerability has been patched.
What type of vulnerability is CVE-2026-53247?
CVE-2026-53247 is classified as a Use After Free vulnerability.
Which software is affected by CVE-2026-53247?
CVE-2026-53247 affects the MediaTek mtk_eth_soc component in the Linux kernel.
What are the potential impacts of CVE-2026-53247?
The potential impacts of CVE-2026-53247 may include system instability or exploitation by attackers resulting from improper memory management.