PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-68126 Linux CVE debrief

A use-after-free vulnerability was found in the Linux kernel's mac802154 subsystem. The mac802154_scan_worker() function captures a scanning sub-interface under RCU and then keeps dereferencing the netdev after rcu_read_unlock() and outside the rtnl. A concurrent DEL_INTERFACE or PHY removal can unregister the interface once the worker drops the rtnl between its two drv_set_channel() sections, leading to a KASAN slab-use-after-free bug.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-08-17
Advisory published
2026-08-10
Advisory updated
2026-08-17

Who should care

Linux kernel developers and users, network administrators, and security teams responsible for Linux kernel-based systems should be aware of this vulnerability and take necessary actions to mitigate it. They should review the Linux kernel version and patches applied, assess the network configuration and mac802154 subsystem usage, and monitor for suspicious TRIGGER_SCAN and DEL_INTERFACE operations.

Technical summary

The mac802154_scan_worker() function in the Linux kernel captures a scanning sub-interface under RCU and then keeps dereferencing the netdev after rcu_read_unlock() and outside the rtnl. A concurrent DEL_INTERFACE or PHY removal can unregister the interface once the worker drops the rtnl between its two drv_set_channel() sections, leading to a KASAN slab-use-after-free bug. This issue can be mitigated by applying the patch to pin the netdev with netdev_hold() while the RCU read lock is still held.

Defensive priority

High

Recommended defensive actions

  • Apply the patch to pin the netdev with netdev_hold() while the RCU read lock is still held
  • Verify and apply any available vendor patches or updates
  • Monitor for and restrict TRIGGER_SCAN and DEL_INTERFACE operations
  • Implement compensating controls to detect and prevent exploitation
  • Review the Linux kernel version and patches applied
  • Assess the network configuration and mac802154 subsystem usage
  • Track exceptions and retest remediated assets

Evidence notes

The vulnerability was resolved by pinning the netdev with netdev_hold() while the RCU read lock is still held, and releasing it at every worker exit. The issue is reachable by racing TRIGGER_SCAN against DEL_INTERFACE (both CAP_NET_ADMIN). To verify and mitigate this vulnerability, defenders should review the Linux kernel version and patches applied, assess the network configuration and mac802154 subsystem usage, and monitor for suspicious TRIGGER_SCAN and DEL_INTERFACE operations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-68126 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-68126

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-68126 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-68126

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/234e5e898b713bc0b3a631b6f002897f43d046c8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/59c1d5463b7bc5a2cdaae27108d1dfd67edc7d1b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5f303f622f6bb8907c405e5123a0ab0f70fb0065

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bd7110f0caa32426140ff302a209c53294ef2cfd

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/dd4754194a706163294b6141460101b99082c8c7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.