Answer in brief
CVE-2026-63797 records a Unknown severity vulnerability in rpmsg: char: Fix use-after-free on probe error path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bc69d10665690492421d926b1cd9a7a36bffd691 <1306fc4f76f765727a6d5aefbf08ef0c8f32996f || >=bc69d10665690492421d926b1cd9a7a36bffd691 <ddf13f91ca82c94ef7ad9c41a434a03313f8eb1b || >=bc69d10665690492421d926b1cd9a7a36bffd691 <c5ebb06c7e24d531b68707168e04698859d642bc || >=bc69d10665690492421d926b1cd9a7a36bffd691 <104d100212396801f1d9d388282f746e23e2bfd6 || >=bc69d10665690492421d926b1cd9a7a36bffd691 <ff268cd9ccbce6472a0658791b417bf11c31ee39 || >=bc69d10665690492421d926b1cd9a7a36bffd691 <1ff3f528e67d20e2b1483dcaba899dc7832b2e6b | 1306fc4f76f765727a6d5aefbf08ef0c8f32996f, ddf13f91ca82c94ef7ad9c41a434a03313f8eb1b, c5ebb06c7e24d531b68707168e04698859d642bc, 104d100212396801f1d9d388282f746e23e2bfd6, ff268cd9ccbce6472a0658791b417bf11c31ee39, 1ff3f528e67d20e2b1483dcaba899dc7832b2e6b |
| Linux/Linuxgeneric | 5.18 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Fix use-after-free on probe error path rpmsg_chrdev_probe() stores the newly allocated eptdev in the default endpoint's priv pointer before calling rpmsg_chrdev_eptdev_add(). If rpmsg_chrdev_eptdev_add() then fails, its error path frees eptdev while the default endpoint may still dispatch callbacks with the stale priv pointer. Avoid publishing eptdev through the default endpoint until rpmsg_chrdev_eptdev_add() succeeds. Messages received before the priv pointer is published should be ignored by rpmsg_ept_cb(). Flow-control updates can hit rpmsg_ept_flow_cb() in the same window, so make both callbacks return success when priv is NULL.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-63797 records a Unknown severity vulnerability in rpmsg: char: Fix use-after-free on probe error path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bc69d10665690492421d926b1cd9a7a36bffd691 <1306fc4f76f765727a6d5aefbf08ef0c8f32996f || >=bc69d10665690492421d926b1cd9a7a36bffd691 <ddf13f91ca82c94ef7ad9c41a434a03313f8eb1b || >=bc69d10665690492421d926b1cd9a7a36bffd691 <c5ebb06c7e24d531b68707168e04698859d642bc || >=bc69d10665690492421d926b1cd9a7a36bffd691 <104d100212396801f1d9d388282f746e23e2bfd6 || >=bc69d10665690492421d926b1cd9a7a36bffd691 <ff268cd9ccbce6472a0658791b417bf11c31ee39 || >=bc69d10665690492421d926b1cd9a7a36bffd691 <1ff3f528e67d20e2b1483dcaba899dc7832b2e6b | 1306fc4f76f765727a6d5aefbf08ef0c8f32996f, ddf13f91ca82c94ef7ad9c41a434a03313f8eb1b, c5ebb06c7e24d531b68707168e04698859d642bc, 104d100212396801f1d9d388282f746e23e2bfd6, ff268cd9ccbce6472a0658791b417bf11c31ee39, 1ff3f528e67d20e2b1483dcaba899dc7832b2e6b |
| Linux/Linuxgeneric | 5.18 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Fix use-after-free on probe error path rpmsg_chrdev_probe() stores the newly allocated eptdev in the default endpoint's priv pointer before calling rpmsg_chrdev_eptdev_add(). If rpmsg_chrdev_eptdev_add() then fails, its error path frees eptdev while the default endpoint may still dispatch callbacks with the stale priv pointer. Avoid publishing eptdev through the default endpoint until rpmsg_chrdev_eptdev_add() succeeds. Messages received before the priv pointer is published should be ignored by rpmsg_ept_cb(). Flow-control updates can hit rpmsg_ept_flow_cb() in the same window, so make both callbacks return success when priv is NULL.
Quoted source text, attributed separately from HOL analysis.