PT-2026-94405 · Linux · Linux Kernel
CVE-2026-90057
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A slab-use-after-free read occurs in the
slip receive buf() function during a race condition with tty hangup. The tty ldisc hangup() function calls ld->ops->hangup() while holding only a read lock on tty->ldisc sem. Since slip hangup() calls slip close(), it can execute concurrently with reader functions like slip receive buf(). Consequently, slip close() unregisters and frees the net device and its private struct slip, leading concurrent reader threads in slip receive buf() to dereference memory that has already been freed.Recommendations
Remove the
slip hangup() function to ensure that teardown is serialized through slip close().Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel