PT-2026-94405 · Linux · Linux Kernel

CVE-2026-90057

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A slab-use-after-free read occurs in the slip receive buf() function during a race condition with tty hangup. The tty ldisc hangup() function calls ld->ops->hangup() while holding only a read lock on tty->ldisc sem. Since slip hangup() calls slip close(), it can execute concurrently with reader functions like slip receive buf(). Consequently, slip close() unregisters and frees the net device and its private struct slip, leading concurrent reader threads in slip receive buf() to dereference memory that has already been freed.
Recommendations Remove the slip hangup() function to ensure that teardown is serialized through slip close().

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102930
CVE-2026-90057
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel