Answer in brief
CVE-2026-53089 records a Unknown severity vulnerability in bpf: Fix use-after-free in offloaded map/prog info fill. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=675fc275a3a2d905535207237402c6d8dcb5fa4b <43d6848a2a6c92ccfd614d9f0bb6fd85b95dfa9d || >=675fc275a3a2d905535207237402c6d8dcb5fa4b <642943ae5bdacabc8109dc4a5e0ebb4a6b99ef3e || >=675fc275a3a2d905535207237402c6d8dcb5fa4b <fea55b034328feaafef75aee252f305e6f85a991 || >=675fc275a3a2d905535207237402c6d8dcb5fa4b <5662dac41a3442aa378d7c405164903eb109fc05 || >=675fc275a3a2d905535207237402c6d8dcb5fa4b <1a2dc103e16448d022a77ad5fc3234641436c4b7 || >=675fc275a3a2d905535207237402c6d8dcb5fa4b <85dc711f742b192eb97c0e00b521312f5a7a415e || >=675fc275a3a2d905535207237402c6d8dcb5fa4b <a51e7fbe94a87e236631a83973d4f558310b2cd2 || >=675fc275a3a2d905535207237402c6d8dcb5fa4b <a0c584fc18056709c8e047a82a6045d6c209f4ce | 43d6848a2a6c92ccfd614d9f0bb6fd85b95dfa9d, 642943ae5bdacabc8109dc4a5e0ebb4a6b99ef3e, fea55b034328feaafef75aee252f305e6f85a991, 5662dac41a3442aa378d7c405164903eb109fc05, 1a2dc103e16448d022a77ad5fc3234641436c4b7, 85dc711f742b192eb97c0e00b521312f5a7a415e, a51e7fbe94a87e236631a83973d4f558310b2cd2, a0c584fc18056709c8e047a82a6045d6c209f4ce |
| Linux/Linuxgeneric | 4.16 | Not reported |
Published upstream
Jun 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free in offloaded map/prog info fill When querying info for an offloaded BPF map or program, bpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns() obtain the network namespace with get_net(dev_net(offmap->netdev)). However, the associated netdev's netns may be racing with teardown during netns destruction. If the netns refcount has already reached 0, get_net() performs a refcount_t increment on 0, triggering: refcount_t: addition on 0; use-after-free. Although rtnl_lock and bpf_devs_lock ensure the netdev pointer remains valid, they cannot prevent the netns refcount from reaching zero. Fix this by using maybe_get_net() instead of get_net(). maybe_get_net() uses refcount_inc_not_zero() and returns NULL if the refcount is already zero, which causes ns_get_path_cb() to fail and the caller to return -ENOENT -- the correct behavior when the netns is being destroyed.
Quoted source text, attributed separately from HOL analysis.