Answer in brief
CVE-2026-53389 records a Unknown severity vulnerability in net/tcp-ao: fix use-after-free of key in del_async path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d6732b95b6fbbc6d5bb9d2f809e275763640c4a2 <6ce7ef41743740ce15c2061561b784148b565b3f || >=d6732b95b6fbbc6d5bb9d2f809e275763640c4a2 <e77fbefd1269b5c123e7c651a1ebdce1b87d19a0 || >=d6732b95b6fbbc6d5bb9d2f809e275763640c4a2 <7ddc29a094d96e9b3aa280433c6dc443df9eabf2 || >=d6732b95b6fbbc6d5bb9d2f809e275763640c4a2 <5ba9950bc9078e19b69cca1e56d1553b125c6857 | 6ce7ef41743740ce15c2061561b784148b565b3f, e77fbefd1269b5c123e7c651a1ebdce1b87d19a0, 7ddc29a094d96e9b3aa280433c6dc443df9eabf2, 5ba9950bc9078e19b69cca1e56d1553b125c6857 |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: fix use-after-free of key in del_async path In tcp_ao_delete_key(), the del_async path skips the current_key and rnext_key validity checks present in the synchronous path, assuming these pointers are always NULL on LISTEN sockets. However, if a key was added with set_current=1/set_rnext=1 while the socket was in CLOSE state, current_key and rnext_key will be non-NULL after listen() transitions the socket to LISTEN. When such a key is deleted with del_async=1, hlist_del_rcu() and call_rcu() free the key without clearing the dangling pointers. After the RCU grace period, getsockopt(TCP_AO_INFO) dereferences current_key->sndid and rnext_key->rcvid from freed slab memory. Clear current_key and rnext_key in the del_async path when they reference the key being deleted.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-53389 records a Unknown severity vulnerability in net/tcp-ao: fix use-after-free of key in del_async path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d6732b95b6fbbc6d5bb9d2f809e275763640c4a2 <6ce7ef41743740ce15c2061561b784148b565b3f || >=d6732b95b6fbbc6d5bb9d2f809e275763640c4a2 <e77fbefd1269b5c123e7c651a1ebdce1b87d19a0 || >=d6732b95b6fbbc6d5bb9d2f809e275763640c4a2 <7ddc29a094d96e9b3aa280433c6dc443df9eabf2 || >=d6732b95b6fbbc6d5bb9d2f809e275763640c4a2 <5ba9950bc9078e19b69cca1e56d1553b125c6857 | 6ce7ef41743740ce15c2061561b784148b565b3f, e77fbefd1269b5c123e7c651a1ebdce1b87d19a0, 7ddc29a094d96e9b3aa280433c6dc443df9eabf2, 5ba9950bc9078e19b69cca1e56d1553b125c6857 |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: fix use-after-free of key in del_async path In tcp_ao_delete_key(), the del_async path skips the current_key and rnext_key validity checks present in the synchronous path, assuming these pointers are always NULL on LISTEN sockets. However, if a key was added with set_current=1/set_rnext=1 while the socket was in CLOSE state, current_key and rnext_key will be non-NULL after listen() transitions the socket to LISTEN. When such a key is deleted with del_async=1, hlist_del_rcu() and call_rcu() free the key without clearing the dangling pointers. After the RCU grace period, getsockopt(TCP_AO_INFO) dereferences current_key->sndid and rnext_key->rcvid from freed slab memory. Clear current_key and rnext_key in the del_async path when they reference the key being deleted.
Quoted source text, attributed separately from HOL analysis.