SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-63797

HIGH · CVSS 8.4 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the Linux kernel's rpmsg subsystem can lead to potential exploitation, as it allows callbacks to access a stale pointer after a probe error. This flaw could enable attackers to execute arbitrary code or cause denial of service, affecting systems relying on the rpmsg character device interface. Organizations using Linux kernel versions impacted by this vulnerability should prioritize patching to mitigate the associated risks.

CVE
CVE-2026-63797
Severity
HIGH
CVSS
8.4
EPSS
0.15%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Fix use-after-free on probe error path rpmsg_chrdev_probe() stores the newly allocated eptdev in the default endpoint's priv pointer before calling rpmsg_chrdev_eptdev_add(). If rpmsg_chrdev_eptdev_add() then fails, its error path frees eptdev while the default endpoint may still dispatch callbacks with the stale priv pointer. Avoid publishing eptdev through the default endpoint until rpmsg_chrdev_eptdev_add() succeeds. Messages received before the priv pointer is published should be ignored by rpmsg_ept_cb(). Flow-control updates can hit rpmsg_ept_flow_cb() in the same window, so make both callbacks return success when priv is NULL.

Related CVEs

Other vulnerabilities affecting the same vendor(s)