idpf: fix double free and use-after-free in aux device error paths
Published Jun 26, 2026
7.8
HIGHCVSS 3.1
EPSS 0.17%
Description
When auxiliary_device_add() fails in idpf_plug_vport_aux_dev() or idpf_plug_core_aux_dev(), the err_aux_dev_add label calls auxiliary_device_uninit() and falls through to err_aux_dev_init. The uninit call will trigger put_device(), which invokes the release callback (idpf_vport_adev_release / idpf_core_adev_release) that frees iadev. The fall-through then reads adev->id from the freed iadev for ida_free() and double-frees iadev with kfree().
Free the IDA slot and clear the back-pointer before uninit, while adev is still valid, then return immediately.
Commit 65637c3a1811 ("idpf: fix UAF in RDMA core aux dev deinitialization") fixed the same use-after-free in the matching unplug path in this file but missed both probe error paths.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 6.17
Unaffected
- ≥ 0, < 6.17
- ≥ 6.18.33, ≤ 6.18.*
- ≥ 7.0.10, ≤ 7.0.*
- 7.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 6.17 · < 6.18.33
- ≥ 6.19 · < 7.0.10
- 7.1
- 7.1
- 7.1
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-53286 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2493742 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39891 Advisory
- https://git.kernel.org/stable/c/6c77b9510829a424d1b74409b7db9456e3522871 Patch
- https://git.kernel.org/stable/c/722b91d5086a249318c9d0e2b36aeac80ba8c808 Patch
- https://git.kernel.org/stable/c/f319de7074e1728a9f9ff7134257360c694ec2b2 Patch
- https://lore.kernel.org/linux-cve-announce/2026062616-CVE-2026-53286-b01e@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-53286
- https://www.cve.org/CVERecord?id=CVE-2026-53286
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data