Description
In the Linux kernel, the following vulnerability has been resolved:

slip: remove slip_hangup() to fix use-after-free in slip_receive_buf()

Jaeyoung Chung and Eulgyu Kim reported a slab-use-after-free read
in slip_receive_buf() when racing against tty hangup.

tty_ldisc_hangup() calls ld->ops->hangup() while holding only
a read lock on tty->ldisc_sem (via tty_ldisc_ref()).
Because slip_hangup() simply called slip_close(), it ran concurrently
with reader functions such as slip_receive_buf().

slip_close() unregisters and frees the net device and its private
struct slip, causing concurrent reader threads in slip_receive_buf()
to dereference freed memory.

Line discipline close() is already guaranteed to be called under
the write lock of tty->ldisc_sem during hangup processing
(in tty_ldisc_reinit() or tty_ldisc_kill()).

Remove slip_hangup() so teardown is serialized cleanly by slip_close().
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free leading to potential information disclosure or crash
Action: Immediate Patch
AI Analysis

Impact

A slab use‑after‑free occurs in slip_receive_buf() when a tty hangs up concurrently; slip_hangup() calls slip_close() which unregisters and frees the net device. A reader in slip_receive_buf() can then dereference freed memory, potentially allowing an attacker to read arbitrary kernel memory or trigger a crash. The weakness is a use‑after‑free flaw that can impact confidentiality and system stability.

Affected Systems

The vulnerability affects the Linux kernel’s slip line‑discipline driver. No specific kernel versions are listed; any build that enables the slip protocol is potentially affected until the issue is patched.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score is below 1 %, suggesting low likelihood of exploitation as of the current data, and the flaw is not yet listed in CISA’s KEV catalog. Attackers would need to trigger the race condition by causing a tty hangup while the slip protocol is in use; this likely requires local privileges or the ability to control a tty device. Once triggered, the use‑after‑free could expose kernel memory or destabilize the system, but no community‑reported exploits are known at this time.

Generated by OpenCVE AI on September 20, 2026 at 04:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that incorporates the patch removing slip_hangup() (commit references in the advisories).
  • If the system cannot be patched immediately, disable the slip driver or module and remove any serial interfaces that rely on slip to prevent the race from occurring.
  • Verify that no legacy slip configuration files remain active and that the system does not load the slip module during boot.

Generated by OpenCVE AI on September 20, 2026 at 04:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: slip: remove slip_hangup() to fix use-after-free in slip_receive_buf() Jaeyoung Chung and Eulgyu Kim reported a slab-use-after-free read in slip_receive_buf() when racing against tty hangup. tty_ldisc_hangup() calls ld->ops->hangup() while holding only a read lock on tty->ldisc_sem (via tty_ldisc_ref()). Because slip_hangup() simply called slip_close(), it ran concurrently with reader functions such as slip_receive_buf(). slip_close() unregisters and frees the net device and its private struct slip, causing concurrent reader threads in slip_receive_buf() to dereference freed memory. Line discipline close() is already guaranteed to be called under the write lock of tty->ldisc_sem during hangup processing (in tty_ldisc_reinit() or tty_ldisc_kill()). Remove slip_hangup() so teardown is serialized cleanly by slip_close().
Title slip: remove slip_hangup() to fix use-after-free in slip_receive_buf()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:52:47.908Z

Reserved: 2026-09-11T19:38:34.784Z

Link: CVE-2026-90057

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:54.310

Modified: 2026-09-18T18:17:40.053

Link: CVE-2026-90057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:15:17Z

Weaknesses