Executive brief
A vulnerability in ESET security software for Linux could allow an attacker with high-level system access to crash the computer. By triggering a specific sequence of system commands, the attacker can cause a 'kernel panic,' which immediately shuts down the server or workstation. This results in a complete service outage (denial-of-service) until the system is manually restarted.
Technical details
A use-after-free (UAF) vulnerability exists in ESET Endpoint Antivirus and Server Security for Linux (CWE-416). The flaw is triggered when a long-running syscall causes the product to access memory pages that have already been released. An attacker with high privileges (PR:H) can exploit this timing-sensitive condition locally to induce a kernel panic, leading to a complete system crash (Denial of Service). The issue has been resolved in multiple version branches, including Endpoint Antivirus 13.2.3.0+ and Server Security 13.2.53.0+.
Affected products
- ESET ESET Endpoint Antivirus for Linux 12.0.13.0 and earlier, 12.1.1.0 and earlier, 12.2.8.0 and earlier, 13.0.3.0 and earlier, 13.1.3.0 and earlier
- ESET ESET Server Security for Linux 12.0.287.0 and earlier, 12.1.406.0 and earlier, 12.2.72.0 and earlier, 13.0.34.0 and earlier, 13.1.116.0 and earlier
Timeline
- 2026-07-15: advisory: Initial advisory published by ESET (CA8972)
- 2026-07-16: disclosed: CVE-2026-6424 published to NVD