cbcvebase.
CVE-2026-53055
published 2026-06-24

CVE-2026-53055: In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-free for sec During packet transmission, if…

PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.43%
35.1th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-free for sec During packet transmission, if the system is under heavy load, the hardware might complete processing the packet and free the request memory (req) before the transmission function finishes. If the software subsequently accesses this req, a use-after-free error will occur. The qp_ctx memory exists throughout the packet sending process, so replace the req with the qp_ctx.

Affected

4 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= f0ae287c50455f7be0d8dd45a803d403c7aa4d2e < b375c3c7209cc59e40e97998aa9bc768369cca0eb375c3c7209cc59e40e97998aa9bc768369cca0e
linuxlinux>= f0ae287c50455f7be0d8dd45a803d403c7aa4d2e < ad73563f3a1edbfddf2724136c6a15826b354e18ad73563f3a1edbfddf2724136c6a15826b354e18
linuxlinux>= f0ae287c50455f7be0d8dd45a803d403c7aa4d2e < 67b53a660e6bf0da2fa8d8872e897a14d8059eaf67b53a660e6bf0da2fa8d8872e897a14d8059eaf
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.