Junglewise Threat Intelligence

CVE-2026-52947: Linux Kernel use-after-free in QRTR qrtr_port_remove

CVE-2026-52947 · Severity: info · CVSS 5.5 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Qualcomm IPC Router (QRTR) networking component. This component is responsible for managing communication between different processors on a device. An exploit could lead to a system crash or potentially allow unauthorized access to memory, impacting the stability and security of the affected system.

Technical details

A race condition exists in net/qrtr/af_qrtr.c within the qrtr_port_remove() function. The root cause is a violation of the RCU (Read-Copy-Update) paradigm where the socket reference count is decremented via __sock_put() before the port is removed from the qrtr_ports XArray and before the RCU grace period expires. This allows concurrent RCU readers, such as qrtr_reset_ports() or qrtr_port_lookup(), to obtain a pointer to a socket and attempt to increment the reference count of an object already marked for deletion. This can result in refcount saturation or a use-after-free (UAF) scenario. The fix involves deferring the reference count decrement until after the XArray erasure and RCU synchronization are complete.

Affected products

  • Linux Linux Kernel bdabad3e363d to 2aa4c12723fe432e623462a3be42a197a128722b

Timeline

  • 2026-06-04: disclosed: Patch submitted by Mingyu Wang
  • 2026-06-19: patched: Commits merged into stable branches by Greg Kroah-Hartman
  • 2026-06-24: advisory: CVE-2026-52947 published

References

Related threats