PatchSiren cyber security CVE debrief
CVE-2026-68126 Linux CVE debrief
A use-after-free vulnerability was found in the Linux kernel's mac802154 subsystem. The mac802154_scan_worker() function captures a scanning sub-interface under RCU and then keeps dereferencing the netdev after rcu_read_unlock() and outside the rtnl. A concurrent DEL_INTERFACE or PHY removal can unregister the interface once the worker drops the rtnl between its two drv_set_channel() sections, leading to a KASAN slab-use-after-free bug.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-17
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-17
Who should care
Linux kernel developers and users, network administrators, and security teams responsible for Linux kernel-based systems should be aware of this vulnerability and take necessary actions to mitigate it. They should review the Linux kernel version and patches applied, assess the network configuration and mac802154 subsystem usage, and monitor for suspicious TRIGGER_SCAN and DEL_INTERFACE operations.
Technical summary
The mac802154_scan_worker() function in the Linux kernel captures a scanning sub-interface under RCU and then keeps dereferencing the netdev after rcu_read_unlock() and outside the rtnl. A concurrent DEL_INTERFACE or PHY removal can unregister the interface once the worker drops the rtnl between its two drv_set_channel() sections, leading to a KASAN slab-use-after-free bug. This issue can be mitigated by applying the patch to pin the netdev with netdev_hold() while the RCU read lock is still held.
Defensive priority
High
Recommended defensive actions
- Apply the patch to pin the netdev with netdev_hold() while the RCU read lock is still held
- Verify and apply any available vendor patches or updates
- Monitor for and restrict TRIGGER_SCAN and DEL_INTERFACE operations
- Implement compensating controls to detect and prevent exploitation
- Review the Linux kernel version and patches applied
- Assess the network configuration and mac802154 subsystem usage
- Track exceptions and retest remediated assets
Evidence notes
The vulnerability was resolved by pinning the netdev with netdev_hold() while the RCU read lock is still held, and releasing it at every worker exit. The issue is reachable by racing TRIGGER_SCAN against DEL_INTERFACE (both CAP_NET_ADMIN). To verify and mitigate this vulnerability, defenders should review the Linux kernel version and patches applied, assess the network configuration and mac802154 subsystem usage, and monitor for suspicious TRIGGER_SCAN and DEL_INTERFACE operations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-68126 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-68126
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-68126 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-68126
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/234e5e898b713bc0b3a631b6f002897f43d046c8
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/59c1d5463b7bc5a2cdaae27108d1dfd67edc7d1b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5f303f622f6bb8907c405e5123a0ab0f70fb0065
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/bd7110f0caa32426140ff302a209c53294ef2cfd
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/dd4754194a706163294b6141460101b99082c8c7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.