CVE-2026-53294
In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: don't free the reused channel The RX channel can be aliased to the TX channel if it has a different MMIO.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: don't free the reused channel The RX channel can be aliased to the TX channel if it has a different MMIO. This special case needs to be handled when freeing the channels otherwise a double-free occurs.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.13% probability · 3th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-415
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/240c71a2aea36a1a4210f911a1c32ea88777e8e4Patch
- https://git.kernel.org/stable/c/3afca89fae501dbd7421e1777b5b8f033b1d98d0Patch
- https://git.kernel.org/stable/c/5c209299b0113e289e238fa5f2e8f00c59f76060Patch
- https://git.kernel.org/stable/c/5d4f3d0f64f1016cb78b400a70b67df91fac99b5Patch
- https://git.kernel.org/stable/c/82f6dcea46cf5de65c4ba7283f7c7b34de4a324dPatch
- https://git.kernel.org/stable/c/88ebadbf0deefdaccdab868b44ff70a0a257f473Patch
- https://git.kernel.org/stable/c/c494a11da45ad7ec9b0ff216c3e3ace351193bb6Patch
- https://git.kernel.org/stable/c/fc0089f82c3e36060c2c79156bc2018bfb16b56bPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.