Junglewise Threat Intelligence

CVE-2026-93134: Linux kernel printk console use-after-free

CVE-2026-93134 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's printk logging system contains a use-after-free vulnerability in console handling. When the kernel emits log records through legacy printing pathways, a handover to another printing context can occur, invalidating the console pointer before it is used again. This could lead to kernel memory corruption or system crashes affecting system stability and reliability.

Technical details

The vulnerability is a use-after-free condition in the console_flush_one_record() function within kernel/printk/printk.c. When legacy printing emits a record, the console SRCU read lock may be released during context handover, invalidating the console struct pointer. The vulnerable code was accessing the @con pointer after calling nbcon_legacy_emit_next_record() or console_emit_next_record() without first checking whether a handover occurred. The fix involves moving the @con pointer access (printk_seq assignment) to occur only after the handover check, ensuring the SRCU lock is still held. The vulnerability affects multiple kernel versions and was patched by moving the console struct reference after the handover validation check.

Affected products

  • Linux Linux Kernel 2.6.11 and later through 7.2

Timeline

  • 2026-09-17: disclosed
  • 2026-07-09: patched: Mainline fix committed by Petr Mladek
  • 2026-09-14: patched: Upstream backport by Greg Kroah-Hartman

References

Related threats