PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72024 Linux CVE debrief

A use-after-free vulnerability was found in the Linux kernel's mac802154 implementation. The bulk hardware teardown path removes entries with list_del(), which can lead to an asynchronous transmit completion following a poisoned list node in ieee802154_wake_queue(). This vulnerability affects Linux kernel developers, maintainers, and users who rely on the mac802154 implementation. They should assess potential exposure, apply patches or updates, and monitor for potential exploit attempts or suspicious activity. The vulnerability is related to the mac802154 implementation in the Linux kernel, and further analysis is required to fully understand the impact and affected scope. Defensive verification tasks are necessary to confirm affected systems and assess potential impact. The CVE record and NVD entry provide limited information about the vulnerability.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers, maintainers, and users who rely on the mac802154 implementation should be aware of this vulnerability and take necessary actions to mitigate it. They should assess potential exposure, apply patches or updates, and monitor for potential exploit attempts or suspicious activity. Security teams and vulnerability management teams should also be aware of this vulnerability and review compensating controls for exposed systems.

Technical summary

The Linux kernel's mac802154 implementation is vulnerable to a use-after-free attack. The bulk hardware teardown path removes entries with list_del(), which can lead to an asynchronous transmit completion following a poisoned list node in ieee802154_wake_queue(). To mitigate this vulnerability, it is recommended to apply patches or updates provided by the Linux kernel maintainers. Affected Linux kernel developers, maintainers, and users should assess potential exposure and take necessary actions.

Defensive priority

Medium

Recommended defensive actions

  • Inventory and assess Linux kernel versions for potential exposure
  • Apply patches or updates provided by the Linux kernel maintainers
  • Monitor for potential exploit attempts or suspicious activity
  • Consider implementing compensating controls, such as network segmentation or access controls
  • Review and verify affected scope and severity with the Linux kernel maintainers
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further analysis is required to fully understand the impact and affected scope. Linux kernel developers and maintainers should verify the vulnerability details and assess potential exposure. The vulnerability is related to the mac802154 implementation in the Linux kernel. Defensive verification tasks are necessary to confirm affected systems and assess potential impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72024 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72024

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72024 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72024

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2039f27b1a0c997137a5de7f8a3cee0e80fbf952

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4bf231f459b542414629b64f63d5cad6701bd07c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/539dfcf69105d8d3d4d677b71de6e5ede2e6dfa0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/72ac5af9ad09662bd0ea91cb8845d490c8ef9c01

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/77caf2d6eba7cb94a7ecd7b369a5974fd7d7c054

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b91e5248dd7af09b500879a46d22a36b60db3a57

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c7c031b75218b3ba3014a0f6b9849888994528d6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.