Junglewise Threat Intelligence

CVE-2026-53120: Linux Kernel use-after-free in PCI driver_override infrastructure

CVE-2026-53120 · Severity: info · CVSS 4.7 · Published 2026-06-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's PCI bus handling that could lead to a system crash or unpredictable behavior. The issue occurs when the system attempts to match hardware devices with their drivers without proper synchronization, potentially allowing a 'use-after-free' condition. This could be exploited by a local attacker to cause a denial of service or potentially gain further unauthorized access.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel PCI subsystem. When a driver is probed via __driver_attach(), the bus' match() callback is invoked without holding the device lock. This allows concurrent access to the driver_override field without synchronization, leading to a race condition and potential UAF. The vulnerability was addressed by migrating the PCI subsystem to the generic driver-core driver_override infrastructure, which implements internal locking. The fix affects multiple components including pci-driver.c, pci-sysfs.c, and vfio_pci_core.c.

Affected products

  • Linux Linux 3.16 to 6.12.91, 6.18.33, 7.0.10

Timeline

  • 2026-06-24: disclosed: Initial publication of the CVE record
  • 2026-06-24: advisory

References