Junglewise Threat Intelligence

CVE-2026-64188: Linux Kernel Qualcomm rmnet use-after-free in rmnet_dellink

CVE-2026-64188 · Severity: info · CVSS 0 · Published 2026-07-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Qualcomm rmnet driver, which handles network data for certain mobile hardware. A flaw in how the system removes network endpoints could allow the system to crash or behave unpredictably when a connection is closed while data is still being processed. This could lead to a local denial-of-service (system crash) affecting device stability.

Technical details

A use-after-free (UAF) vulnerability exists in the rmnet_dellink() function within the Qualcomm rmnet driver (drivers/net/ethernet/qualcomm/rmnet). The root cause is that rmnet_dellink() removes an endpoint from the RCU-protected hash table using hlist_del_init_rcu() but immediately calls kfree() without waiting for an RCU grace period. Consequently, concurrent RCU readers in the receive path (rmnet_rx_handler) may attempt to dereference the endpoint's egress_dev pointer after the memory has been reclaimed, leading to a kernel oops/page fault. The fix introduces an rcu_head to the rmnet_endpoint structure and utilizes kfree_rcu() to ensure memory safety during concurrent access.

Affected products

  • Linux Linux kernel ceed73a2cf4a to c4e676c3505c
  • Linux Linux kernel ceed73a2cf4a to 9918698cf3aee4032e12bb42fd5a951dc465339b

Timeline

  • 2026-05-14: other: Patch submitted by developer
  • 2026-07-04: patched: Commits merged into stable trees
  • 2026-07-20: advisory: CVE published by NVD

References

Related threats