PT-2026-6166 · Linux+2 · Linux Kernel+2
Michele Spagnuolo
·
Published
2026-01-01
·
Updated
2026-05-22
·
CVE-2026-23096
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux Kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel related to the handling of character devices within the uacce module. Specifically, a use-after-free condition can occur during the cleanup process when
cdev device add fails. If cdev device add fails, the associated memory is released, and subsequent execution of cdev device del leads to a hang error. The issue arises from failing to check the return value of cdev device add() and subsequently attempting to call cdev device del in the uacce remove function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Linuxmint
Ubuntu