Junglewise Threat Intelligence

CVE-2026-52982: Linux Kernel rtl8150 use-after-free in rtl8150_start_xmit

CVE-2026-52982 · Severity: info · CVSS 5.5 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's driver for Realtek RTL8150 USB Ethernet adapters. Under specific timing conditions during network data transmission, the system may attempt to access memory that has already been released. This can lead to a system crash or unpredictable behavior, potentially impacting the availability of the affected device or the entire system.

Technical details

A use-after-free (UAF) read vulnerability exists in drivers/net/usb/rtl8150.c within the rtl8150_start_xmit() function. The root cause is a race condition where the sk_buff (skb) is freed by the URB completion handler (write_bulk_callback) on one CPU before the submitter on another CPU finishes accessing skb->len for statistics. An attacker with the ability to trigger network transmissions on a system using this driver could potentially trigger this race condition. The fix involves caching the skb length before submitting the URB to ensure the value is available even if the skb is freed immediately upon submission. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel up to 6.9.1

Timeline

  • 2026-04-23: disclosed: Vulnerability reported by syzbot and patch authored
  • 2026-04-27: patched: Mainline kernel patch committed
  • 2026-06-24: advisory: CVE-2026-52982 published

References

Related threats