Junglewise Threat Intelligence

CVE-2026-45866: Linux Kernel use-after-free in caif_serial ldisc_close

CVE-2026-45866 · Severity: info · CVSS 5.5 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A security vulnerability has been identified in the Linux kernel's CAIF serial driver. This flaw could allow a local attacker to cause a system crash or potentially execute unauthorized actions by exploiting a timing issue when closing certain network connections. The issue specifically affects systems using the CAIF protocol, often used in cellular modem communications.

Technical details

A use-after-free (UAF) vulnerability exists in drivers/net/caif/caif_serial.c due to a race condition between ldisc_close() and caif_xmit(). The root cause is that tty_kref_put() is called in ldisc_close() while the network device is still active. If a packet transmission occurs via handle_tx() during this window, it may access the ser->tty pointer after the tty object has been freed. An attacker can trigger this by initiating a close operation while simultaneously sending packets. The fix involves deferring the tty reference release to ser_release() after the network device has been successfully unregistered.

Affected products

  • Linux Linux Kernel Fixed in 308e7e4d0a846359685f40aade023aee7b27284c and related stable backports

Timeline

  • 2026-02-10: patched: Initial fix committed to mainline kernel
  • 2026-05-27: disclosed: CVE published

References