Junglewise Threat Intelligence

CVE-2026-6424: ESET Linux products use-after-free causing kernel panic

CVE-2026-6424 · Severity: info · CVSS 6.7 · Published 2026-07-16

Vendors: Eset.

Executive brief

A vulnerability in ESET security software for Linux could allow an attacker with high-level system access to crash the computer. By triggering a specific sequence of system commands, the attacker can cause a 'kernel panic,' which immediately shuts down the server or workstation. This results in a complete service outage (denial-of-service) until the system is manually restarted.

Technical details

A use-after-free (UAF) vulnerability exists in ESET Endpoint Antivirus and Server Security for Linux (CWE-416). The flaw is triggered when a long-running syscall causes the product to access memory pages that have already been released. An attacker with high privileges (PR:H) can exploit this timing-sensitive condition locally to induce a kernel panic, leading to a complete system crash (Denial of Service). The issue has been resolved in multiple version branches, including Endpoint Antivirus 13.2.3.0+ and Server Security 13.2.53.0+.

Affected products

  • ESET ESET Endpoint Antivirus for Linux 12.0.13.0 and earlier, 12.1.1.0 and earlier, 12.2.8.0 and earlier, 13.0.3.0 and earlier, 13.1.3.0 and earlier
  • ESET ESET Server Security for Linux 12.0.287.0 and earlier, 12.1.406.0 and earlier, 12.2.72.0 and earlier, 13.0.34.0 and earlier, 13.1.116.0 and earlier

Timeline

  • 2026-07-15: advisory: Initial advisory published by ESET (CA8972)
  • 2026-07-16: disclosed: CVE-2026-6424 published to NVD

References