Answer in brief
CVE-2026-90057 records a Unknown severity vulnerability in slip: remove slip_hangup() to fix use-after-free in slip_receive_buf(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5342b77c4123ba39f911d92a813295fb3bb21f69 <9a3b1edff1ecb47d323f2506b3ffc22178acd1c6 || >=5342b77c4123ba39f911d92a813295fb3bb21f69 <a2dbac3fb03b4427ccf057debc83fc61ee102529 || >=5342b77c4123ba39f911d92a813295fb3bb21f69 <de1f978c0f6ab42b28192d74dc59af52fdc76135 || >=5342b77c4123ba39f911d92a813295fb3bb21f69 <ddbc5dc5a2e29b3934da09c1ba3c930fd8a40fd6 || >=5342b77c4123ba39f911d92a813295fb3bb21f69 <a540a49fcca59d1c92c3a6462e67ca21676a88df || >=5342b77c4123ba39f911d92a813295fb3bb21f69 <23c53269f2baaedf2d92784290cb9ef6db2a3bce | 9a3b1edff1ecb47d323f2506b3ffc22178acd1c6, a2dbac3fb03b4427ccf057debc83fc61ee102529, de1f978c0f6ab42b28192d74dc59af52fdc76135, ddbc5dc5a2e29b3934da09c1ba3c930fd8a40fd6, a540a49fcca59d1c92c3a6462e67ca21676a88df, 23c53269f2baaedf2d92784290cb9ef6db2a3bce |
| Linux/Linuxgeneric | 2.6.32 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: slip: remove slip_hangup() to fix use-after-free in slip_receive_buf() Jaeyoung Chung and Eulgyu Kim reported a slab-use-after-free read in slip_receive_buf() when racing against tty hangup. tty_ldisc_hangup() calls ld->ops->hangup() while holding only a read lock on tty->ldisc_sem (via tty_ldisc_ref()). Because slip_hangup() simply called slip_close(), it ran concurrently with reader functions such as slip_receive_buf(). slip_close() unregisters and frees the net device and its private struct slip, causing concurrent reader threads in slip_receive_buf() to dereference freed memory. Line discipline close() is already guaranteed to be called under the write lock of tty->ldisc_sem during hangup processing (in tty_ldisc_reinit() or tty_ldisc_kill()). Remove slip_hangup() so teardown is serialized cleanly by slip_close().
Quoted source text, attributed separately from HOL analysis.