AUGUST 22, 2026
Live Feed
Back to database
Case File

CVE-2026-68423

UNKNOWN · CVSS N/A EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

A use-after-free vulnerability exists in the Linux kernel's mtd_virt_concat_destroy() function, which can lead to potential memory corruption issues when mtd_virt_concat_put_mtd_devices() is called after freeing item->concat. This flaw could be exploited to execute arbitrary code or cause system instability. Organizations using affected Linux kernel versions should prioritize patching this vulnerability to mitigate risks associated with memory management errors.

CVE
CVE-2026-68423
Severity
UNKNOWN
CVSS
N/A
EPSS
0.14%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy() mtd_concat_destroy() frees item->concat so calling mtd_virt_concat_put_mtd_devices(item->concat) after that leads to a use-after-free. Fix it by moving mtd_virt_concat_put_mtd_devices() before mtd_concat_destroy().