AUGUST 22, 2026
Live Feed
Back to database
Case File

CVE-2026-68424

UNKNOWN · CVSS N/A EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's MTD (Memory Technology Device) subsystem, specifically in the virt_concat functionality, where a use-after-free condition can occur due to improper ordering of function calls. This flaw could potentially lead to memory corruption and exploitation, impacting system stability and security. Linux system administrators and developers working with MTD devices should prioritize addressing this issue to mitigate potential risks.

CVE
CVE-2026-68424
Severity
UNKNOWN
CVSS
N/A
EPSS
0.14%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy_joins() mtd_concat_destroy() frees item->concat so calling mtd_virt_concat_put_mtd_devices(item->concat) leads to a use after free. Fix this by moving mtd_virt_concat_put_mtd_devices() before mtd_concat_destroy()