PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72079 Linux CVE debrief

A use-after-free and double-free vulnerability was found in the ims-pcu disconnect function of the Linux kernel. The ims_pcu_disconnect function only intended to perform cleanup when the primary control interface is unbound. However, it currently relies on the interface class to distinguish between control and data interfaces. A malicious device could present a data interface with the same class as the control interface, leading to premature cleanup and potential use-after-free or double-free.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux-based systems should be aware of this vulnerability and take precautions to prevent exploitation. They should verify that the Linux kernel is up-to-date with the latest security patches, restrict access to the ims-pcu interface, and monitor system logs for potential use-after-free or double-free errors. Additionally, they should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets that need extra review should be checked. Exceptions, retest remediated assets, and close the item only after evidence is documented should be tracked. System administrators and security teams responsible for Linux-based systems should prioritize patching and mitigation efforts to prevent potential use-after-free or double-free errors. Vulnerability management and security teams should review the vulnerability and assess the risk to their organization. They should also review compensating controls and implement additional security measures to prevent exploitation. Asset owners and operators should review the vulnerability and assess the risk to their assets. They should also review compensating controls and implement additional security measures to prevent exploitation. Security teams should review the vulnerability and assess the risk to their organization. They should also review compensating controls and implement additional security measures to prevent exploitation. IT teams and system administrators should review the vulnerability and assess the risk to their systems. They should also review compensating controls and implement additional security measures to prevent exploitation. Security operations teams should review the vulnerability and assess the risk to their organization. They should also review compensating controls and implement additional security measures to

Technical summary

The ims_pcu_disconnect function in the Linux kernel does not properly verify the interface being disconnected, allowing a malicious device to present a data interface with the same class as the control interface. This can lead to premature cleanup and potential use-after-free or double-free errors. The vulnerability has been resolved, but Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux-based systems should take precautions to prevent exploitation. They should verify that the Linux kernel is up-to-date with the latest security patches, restrict access to the ims-pcu interface, and monitor system logs for potential use-after-free or double-free errors.

Defensive priority

Medium

Recommended defensive actions

  • Verify that the Linux kernel is up-to-date with the latest security patches
  • Restrict access to the ims-pcu interface to prevent malicious devices from presenting a data interface with the same class as the control interface
  • Monitor system logs for potential use-after-free or double-free errors
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide information about the vulnerability in the Linux kernel's ims-pcu disconnect function, which has been resolved. However, the details are limited, and further analysis is required to fully understand the issue. The vulnerability allows a malicious device to present a data interface with the same class as the control interface, leading to premature cleanup and potential use-after-free or double-free errors. Defenders should verify that the Linux kernel is up-to-date with the latest security patches and monitor system logs for potential use-after-free or double-free errors. Additionally, they should restrict access to the ims-pcu interface to prevent malicious devices from presenting a data interface with the same class as the control interface.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72079 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72079

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72079 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72079

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/293388e42e5c0865204de6f36bfb8662156fce3b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/315f269ea04bc1477ab9bf351e939623d12a1621

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/462a999917755a3bf77448dfd64307963cf0a9f0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6a6c373e6a82eddc522342c8a8db7072c65f2b56

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6aacc18004b1a915ccb8a829d30279a37988066e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/921abbb33887052e46b1b77299f87a3c741dc580

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a4b3f4d42fbf58f06f0d49e37a9d0d9392eca338

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.