SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-63930

HIGH · CVSS 7.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

A use-after-free vulnerability exists in the Linux kernel's IIO buffer management, specifically in the error handling path of the iio_hw_consumer_alloc() function. This flaw can lead to potential crashes or arbitrary code execution due to accessing freed memory during buffer iteration. Organizations using affected Linux systems should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-63930
Severity
HIGH
CVSS
7.8
EPSS
0.16%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: iio: buffer: hw-consumer: fix use-after-free in error path In the err_put_buffers cleanup path of iio_hw_consumer_alloc(), the code was using list_for_each_entry() to iterate through buffers while calling iio_buffer_put() which can free the current buffer if refcount drops to 0. The list_for_each_entry() loop macro then evaluates buf->head.next to continue iteration, accessing the freed buffer. Fix this by using list_for_each_entry_safe().