CVE-2026-53248: net: airoha: Fix use-after-free in metadata dst teardown
In the Linux kernel, the following vulnerability has been resolved:
net: airoha: Fix use-after-free in metadata dst teardown
airohametadatadstfree() runs metadatadstfree() which frees the metadatadst with kfree() immediately, bypassing the RCU grace period. In the RX path, skbdstsetnoref() sets a non-refcounted pointer from the skb to the metadatadst. This function requires RCU read-side protection and the dst must remain valid until all RCU readers complete. Since metadatadstfree() calls kfree() directly, an use-after-free can occur if any skb still holds a noref pointer to the dst when the driver tears it down. Replace metadatadstfree() with dstrelease() which properly goes through the refcount path: when the refcount drops to zero, it schedules the actual free via callrcuhurry(), ensuring all RCU readers have completed before the memory is freed.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53248?
CVE-2026-53248 has a severity rating of high, with a score of 8.8.
What type of vulnerability is CVE-2026-53248?
CVE-2026-53248 is categorized as a use-after-free vulnerability in the Linux kernel.
How does CVE-2026-53248 affect system security?
CVE-2026-53248 could allow an attacker to execute arbitrary code or cause a denial of service due to improper memory management.
How can I fix CVE-2026-53248?
To fix CVE-2026-53248, update the Linux kernel to the patched version that addresses the use-after-free issue.
What software is impacted by CVE-2026-53248?
CVE-2026-53248 affects the Linux kernel specifically in the airoha network subsystem.