{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-53160","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.388Z","datePublished":"2026-06-25T08:38:42.138Z","dateUpdated":"2026-08-05T12:33:35.015Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:33:35.015Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: fix use-after-free race in fastrpc_map_create\n\nfastrpc_map_lookup returns a raw pointer after releasing fl->lock. The\ncaller fastrpc_map_create then calls fastrpc_map_get (kref_get_unless_zero)\non this unprotected pointer. A concurrent MEM_UNMAP can free the map\nbetween the lock release and the kref operation, resulting in a\nuse-after-free on the freed slab object.\n\nRestore the take_ref parameter to fastrpc_map_lookup so the reference\nis acquired atomically under fl->lock before the pointer is exposed to\nthe caller."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is reached through local FastRPC misc-device ioctls such as FASTRPC_IOCTL_MEM_MAP, FASTRPC_IOCTL_INVOKE, and FASTRPC_IOCTL_INIT_CREATE. There is no network or adjacent-path entry point.\nAC:L - The attacker can drive both sides of the race by issuing concurrent map-creating and MEM_UNMAP ioctls against the same FastRPC file context and DMA-buf fd. No condition outside attacker control is required beyond scheduling the race.\nPR:L - The ioctl path has no in-driver capable(), namespace capability, or credential check once the FastRPC device node is open. Exploitation requires local access to the device node as a basic user or device-authorized app, not real root.\nUI:N - No victim action is required after the attacker has local access. The attacker directly opens the FastRPC device and submits ioctls.\nS:U - This is a kernel memory safety bug in a local kernel driver and exploitation would affect the same kernel security authority. It is not a VM escape, IOMMU bypass, or other cross-scope boundary violation by itself.\nC:H - The bug is a use-after-free on struct fastrpc_map, a slab object containing pointers and DMA mapping state. Under the required high-severity rule, this memory corruption is treated as capable of enabling kernel information disclosure.\nI:H - The use-after-free can be raced with allocator reuse and involves refcount/list/DMA mapping state, making control of freed object contents plausibly exploitable for kernel memory corruption. Under the kernel guidance, UAFs receive high integrity impact.\nA:H - Even without full exploitation, racing kref_get_unless_zero() and later map-field use on a freed object can trigger kernel warnings, oopses, or crashes. Repeated local ioctls can therefore cause high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/misc/fastrpc.c"],"versions":[{"version":"0b70ec82b309a4093106ff399da1911ad23b52d3","lessThan":"0a3b87293fbd34fda651e6aead9964f84b893962","status":"affected","versionType":"git"},{"version":"d7513b47082c08105e837b06cebeb3f07a5fa56f","lessThan":"8b080c89183196fd3e49212f2a1a1c4a29335b9c","status":"affected","versionType":"git"},{"version":"802359a52676176b18713e33caa17572ad009057","lessThan":"5b0166112019d1dce30b976ab28fd67f7f0be532","status":"affected","versionType":"git"},{"version":"10df039834f84a297c72ec962c0f9b7c8c5ca31a","lessThan":"992f121796b7ca83a5a8b93da24e971363206218","status":"affected","versionType":"git"},{"version":"10df039834f84a297c72ec962c0f9b7c8c5ca31a","lessThan":"f20f6512ecb75c816e0debf4551a138f098615c4","status":"affected","versionType":"git"},{"version":"10df039834f84a297c72ec962c0f9b7c8c5ca31a","lessThan":"07ebe87915d8accdaba20c4f88c5ae430fe62fbb","status":"affected","versionType":"git"},{"version":"f3f59bab68e9bc714f757ab22f3fb36153014043","status":"affected","versionType":"git"},{"version":"6.1.156","lessThan":"6.1.176","status":"affected","versionType":"semver"},{"version":"6.6.112","lessThan":"6.6.143","status":"affected","versionType":"semver"},{"version":"6.12.53","lessThan":"6.12.94","status":"affected","versionType":"semver"},{"version":"6.17.3","lessThan":"6.18","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/misc/fastrpc.c"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.94","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.36","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.13","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.156","versionEndExcluding":"6.1.176"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.112","versionEndExcluding":"6.6.143"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.53","versionEndExcluding":"6.12.94"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"6.18.36"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.0.13"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0a3b87293fbd34fda651e6aead9964f84b893962"},{"url":"https://git.kernel.org/stable/c/8b080c89183196fd3e49212f2a1a1c4a29335b9c"},{"url":"https://git.kernel.org/stable/c/5b0166112019d1dce30b976ab28fd67f7f0be532"},{"url":"https://git.kernel.org/stable/c/992f121796b7ca83a5a8b93da24e971363206218"},{"url":"https://git.kernel.org/stable/c/f20f6512ecb75c816e0debf4551a138f098615c4"},{"url":"https://git.kernel.org/stable/c/07ebe87915d8accdaba20c4f88c5ae430fe62fbb"}],"title":"misc: fastrpc: fix use-after-free race in fastrpc_map_create","x_generator":{"engine":"bippy-1.2.0"}}}}