Junglewise Threat Intelligence

CVE-2026-53247: Linux Kernel mtk_eth_soc use-after-free in metadata dst teardown

CVE-2026-53247 · Severity: info · CVSS 5.5 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the MediaTek Ethernet driver within the Linux kernel. This component is responsible for managing network connectivity on devices using MediaTek hardware. An exploit could lead to a system crash or unpredictable behavior during network device teardown, potentially impacting the availability of the system.

Technical details

A use-after-free (UAF) vulnerability exists in the mtk_eth_soc driver within the Linux kernel. The root cause is the use of metadata_dst_free() in mtk_free_dev(), which immediately invokes kfree() and bypasses the RCU grace period. In the receive (RX) path, skb_dst_set_noref() creates non-refcounted pointers to this metadata that require RCU protection. If a driver teardown occurs while an skb still holds a pointer to the destination, a UAF is triggered. The fix replaces metadata_dst_free() with dst_release(), ensuring the memory is only freed via call_rcu_hurry() after all RCU readers have finished. This is reachable locally during network interface management operations.

Affected products

  • Linux Linux Kernel 6.2 to 7.1

Timeline

  • 2026-06-02: other: Patch authored
  • 2026-06-25: disclosed: CVE published

References

Related threats