Back to overview

CVE-2026-53112

Description
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet The irq_prepare_bcn_tasklet is initialized in rtl_pci_init() and scheduled when RTL_IMR_BCNINT interrupt is triggered by hardware. But it is never killed in rtl_pci_deinit(). When the rtlwifi card probe fails or is being detached, the ieee80211_hw is deallocated. However, irq_prepare_bcn_tasklet may still be running or pending, leading to use-after-free when the freed ieee80211_hw is accessed in _rtl_pci_prepare_bcn_tasklet(). Similar to irq_tasklet, add tasklet_kill() in rtl_pci_deinit() to ensure that irq_prepare_bcn_tasklet is properly terminated before the ieee80211_hw is released. The issue was identified through static analysis.

Metadata

CVE ID
CVE-2026-53112
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-24 16:30 UTC
Last updated
2026-06-24 16:30 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 0c8173385e549f95cd80c3fff5aab87b4f881d8d < ae10d4a1ab6bcaa1336abb171908a9a365761d3e, 0c8173385e549f95cd80c3fff5aab87b4f881d8d < fac1079e0fdec6df6d7562c21941587236dc3def, 0c8173385e549f95cd80c3fff5aab87b4f881d8d < e40873820c9d245ce482faa7ad514ebdb3b8d23d, 0c8173385e549f95cd80c3fff5aab87b4f881d8d < 008c456b76e9070979bc0e763897a5d3b0fdd4dc …
Linux Linux 2.6.38, 0 < 2.6.38, 5.10.258 ≤ 5.10.*, 5.15.209 ≤ 5.15.* …
Back to overview