๐Ÿ” CVE Alert

CVE-2026-72489

UNKNOWN 0.0

staging: nvec: fix use-after-free in nvec_rx_completed()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: staging: nvec: fix use-after-free in nvec_rx_completed() In nvec_rx_completed(), when an incomplete RX transfer is detected, nvec_msg_free() is called to return the message back to the pool by clearing its 'used' atomic flag. Immediately after this, the code accesses nvec->rx->data[0] to check the message type. Since nvec_msg_free() marks the pool slot as available via atomic_set(), any concurrent or subsequent call to nvec_msg_alloc() could claim that same slot and overwrite its data[] array. Reading nvec->rx->data[0] after freeing the message is therefore a use-after-free. Fix this by saving the message type byte before calling nvec_msg_free(), then using the saved value for the battery quirk check.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
d6bdcf2e1019351cbc176e963b7756766bdd8721 < 6b2ea886ebdae44a2394029844a4e78f58e1587d d6bdcf2e1019351cbc176e963b7756766bdd8721 < a37625c7b688fcf68a54263528eccbabfd7fa17a d6bdcf2e1019351cbc176e963b7756766bdd8721 < 9f7fe4165a1f1014bdadc8e744c0fd3c2d8c0b89 d6bdcf2e1019351cbc176e963b7756766bdd8721 < 08626fcfe12308ca3f8b22c538ba7dee0b2dce7a d6bdcf2e1019351cbc176e963b7756766bdd8721 < f19a5bc059051143c489dd6f79a0f9c3bfd13aea d6bdcf2e1019351cbc176e963b7756766bdd8721 < bb3d592c7d6c4ec8ac6640c690ca13298e7e8e90 d6bdcf2e1019351cbc176e963b7756766bdd8721 < 5de04caa46b635e180cecbd164e333eca535db94 d6bdcf2e1019351cbc176e963b7756766bdd8721 < 26813881181deb3a32fbb59eadb2599cbe8423f6
Linux / Linux
3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/6b2ea886ebdae44a2394029844a4e78f58e1587d git.kernel.org: https://git.kernel.org/stable/c/a37625c7b688fcf68a54263528eccbabfd7fa17a git.kernel.org: https://git.kernel.org/stable/c/9f7fe4165a1f1014bdadc8e744c0fd3c2d8c0b89 git.kernel.org: https://git.kernel.org/stable/c/08626fcfe12308ca3f8b22c538ba7dee0b2dce7a git.kernel.org: https://git.kernel.org/stable/c/f19a5bc059051143c489dd6f79a0f9c3bfd13aea git.kernel.org: https://git.kernel.org/stable/c/bb3d592c7d6c4ec8ac6640c690ca13298e7e8e90 git.kernel.org: https://git.kernel.org/stable/c/5de04caa46b635e180cecbd164e333eca535db94 git.kernel.org: https://git.kernel.org/stable/c/26813881181deb3a32fbb59eadb2599cbe8423f6