Executive brief
The SLIP (Serial Line Internet Protocol) driver in the Linux kernel is vulnerable to a use-after-free memory error when a TTY hangup occurs concurrently with data reception. An attacker with local access to a SLIP network device could trigger this race condition to read freed memory, potentially leading to information disclosure or denial of service.
Technical details
This is a use-after-free vulnerability in the SLIP line discipline driver (drivers/net/slip/slip.c). The root cause is that slip_hangup() called slip_close() while holding only a read lock on tty->ldisc_sem, allowing concurrent reader threads in slip_receive_buf() to execute. slip_close() unregisters and frees the network device and its private slip structure, causing concurrent readers to dereference freed memory. The fix removes the slip_hangup() function entirely, relying on slip_close() which is already guaranteed to execute under a write lock during hangup processing (tty_ldisc_reinit or tty_ldisc_kill). The vulnerability requires a race condition between TTY hangup and buffer reception, typically triggered locally.
Affected products
- Linux Linux kernel Multiple (patch applied from 6.11+, backported to stable branches)
Timeline
- 2026-09-17: disclosed: CVE published
- 2026-08-26: patched: Fix committed by Eric Dumazet (commit 23c53269f2baaedf2d92784290cb9ef6db2a3bce)
- 2026-08-25: other: Vulnerability reported by Jaeyoung Chung and Eulgyu Kim