Junglewise Threat Intelligence

CVE-2026-53115: Linux Kernel use-after-free in fsl-mc bus driver

CVE-2026-53115 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Freescale Management Complex (fsl-mc) bus driver. This component is responsible for managing hardware resources in certain embedded and networking systems. An exploit could lead to a system crash or unpredictable behavior due to improper memory handling during hardware driver initialization.

Technical details

A use-after-free (UAF) vulnerability exists in drivers/bus/fsl-mc/fsl-mc-bus.c within the Linux kernel. The issue occurs because the bus's match() callback, triggered during driver probing via __driver_attach(), accesses the driver_override field without holding the necessary device lock. This lack of synchronization allows for a race condition where the field can be modified or freed while being accessed. The fix migrates the fsl-mc bus to the generic driver-core driver_override infrastructure, which implements internal locking to ensure thread safety. This vulnerability requires local access to trigger driver probing or override configurations.

Affected products

  • Linux Linux 5.10 to 6.12.91, 6.18.33, 7.0.10

Timeline

  • 2026-03-24: patched: Initial fix commit authored
  • 2026-06-24: disclosed: CVE published

References