CVE-2026-53248
published 2026-06-25CVE-2026-53248: In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix use-after-free in metadata dst teardown airoha_metadata_dst_free() runs…
PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.39%
31.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: airoha: Fix use-after-free in metadata dst teardown
airoha_metadata_dst_free() runs metadata_dst_free() which frees the
metadata_dst with kfree() immediately, bypassing the RCU grace period.
In the RX path, skb_dst_set_noref() sets a non-refcounted pointer from
the skb to the metadata_dst. This function requires RCU read-side
protection and the dst must remain valid until all RCU readers complete.
Since metadata_dst_free() calls kfree() directly, an use-after-free can
occur if any skb still holds a noref pointer to the dst when the driver
tears it down.
Replace metadata_dst_free() with dst_release() which properly goes
through the refcount path: when the refcount drops to zero, it schedules
the actual free via call_rcu_hurry(), ensuring all RCU readers have
completed before the memory is freed.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= af3cf757d5c99011b9b94ea8d78aeaccc0153fdc < 6f829e2c17a53a35321268339cd252aff6d6d723 | 6f829e2c17a53a35321268339cd252aff6d6d723 |
| linux | linux | >= af3cf757d5c99011b9b94ea8d78aeaccc0153fdc < 4b5a574e033e66d2131eff1c18feef8d8643c67e | 4b5a574e033e66d2131eff1c18feef8d8643c67e |
| linux | linux | >= af3cf757d5c99011b9b94ea8d78aeaccc0153fdc < b38cae85d1c45ff189d7ecb6ac36f41cdc3d84d0 | b38cae85d1c45ff189d7ecb6ac36f41cdc3d84d0 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 6.15 < 6.18.36 | 6.18.36 |
| linux | linux_kernel | >= 6.19 < 7.0.13 | 7.0.13 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: airoha: Fix use-after-free in metadata dst teardown
vendor_redhat·2026-06-25
CVE-2026-53248 CWE-911 kernel: net: airoha: Fix use-after-free in metadata dst teardown
kernel: net: airoha: Fix use-after-free in metadata dst teardown
A flaw was found in the Linux kernel's airoha network driver. This use-after-free vulnerability occurs when the `airoha_metadata_dst_free()` function frees memory prematurely, before all references to it are released. If a network packet still holds a pointer to the freed memory, a use-after-free condition can arise. This could lead to system instability or potentially allow an attacker to escalate privileges.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: k
GHSA
In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix use-after-free in metadata dst teardown airoha_metadata_dst_free() runs metadata_dst_free() which frees the metad
ghsa_unreviewed·2026-06-25
CVE-2026-53248 In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix use-after-free in metadata dst teardown airoha_metadata_dst_free() runs metadata_dst_free() which frees the metad
In the Linux kernel, the following vulnerability has been resolved:
net: airoha: Fix use-after-free in metadata dst teardown
airoha_metadata_dst_free() runs metadata_dst_free() which frees the
metadata_dst with kfree() immediately, bypassing the RCU grace period.
In the RX path, skb_dst_set_noref() sets a non-refcounted pointer from
the skb to the metadata_dst. This function requires RCU read-side
protection and the dst must remain valid until all RCU readers complete.
Since metadata_dst_free() calls kfree() directly, an use-after-free can
occur if any skb still holds a noref pointer to the dst when the driver
tears it down.
Replace metadata_dst_free() with dst_release() which properly goes
through the refcount path: when the refcount drops to zero, it schedules
the actual free via call_
No detection rules found.
No public exploits indexed.
2026-06-25
Published