Junglewise Threat Intelligence

CVE-2026-53389: Linux Kernel use-after-free in TCP-AO key deletion

CVE-2026-53389 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash or potentially access sensitive memory. The issue occurs when specific security keys used for TCP Authentication Option (TCP-AO) are deleted while the system still holds references to them. This could lead to unpredictable system behavior or a denial of service for applications relying on secure network communications.

Technical details

A use-after-free vulnerability exists in net/ipv4/tcp_ao.c within the tcp_ao_delete_key() function. When a TCP-AO key is deleted using the del_async path, the kernel fails to clear current_key and rnext_key pointers if they were set while the socket was in a CLOSE state and subsequently transitioned to LISTEN. An attacker can trigger this by deleting such a key, causing the kernel to maintain dangling pointers that are later dereferenced during a getsockopt(TCP_AO_INFO) call after the RCU grace period. This can lead to kernel memory corruption or a system crash. The issue has been patched by ensuring these pointers are cleared during asynchronous deletion.

Affected products

  • Linux Linux Kernel 6.7 to 7.1.3

Timeline

  • 2026-06-23: other: Vulnerability fixed in upstream kernel source
  • 2026-07-19: disclosed: CVE published

References

Related threats