Description
In the Linux kernel, the following vulnerability has been resolved:

printk: Fix possible console use-after-free

When emitting a record via legacy printing, it is possible that a handover
to another legacy printing context occurs. When a context has performed a
handover, the console SRCU read lock is released and the pointer to the
console struct might now be invalid. Therefore, after calling
nbcon_legacy_emit_next_record() or console_emit_next_record(), it is
necessary to check if a handover occurred _before_ further @con usage.

Sashiko pointed out that console_flush_one_record() was not doing this.

In console_flush_one_record(), after emitting a record, move the further
usage of @con after the handover check.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free leading to potential memory corruption or crash
Action: Patch
AI Analysis

Impact

The Linux kernel bug allows a console use‑after‑free when a legacy printing handover occurs while a console buffer is still in use. After the handover the console SRCU read lock is released, the console struct pointer may become invalid, and subsequent access can dereference freed memory. This flaw can lead to memory corruption or a system crash.

Affected Systems

The vulnerability resides in the Linux kernel itself and affects any system that uses the legacy console printing infrastructure. No specific kernel versions are listed in the CNA information, so the issue may exist across multiple releases until the patch is applied.

Risk and Exploitability

The EPSS score for this vulnerability is below 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not part of known actively exploited vulnerabilities. Therefore, the overall risk assessment is low, though environments that rely on legacy console printing remain vulnerable to a use‑after‑free that could cause memory corruption or a system crash once the handover occurs.

Generated by OpenCVE AI on September 19, 2026 at 07:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for and apply the latest kernel patch that introduces handover checks before accessing the console structure.
  • If a patch is not yet available, consider disabling legacy console printing or redirecting kernel log output to avoid triggering the handover condition.
  • Monitor system logs for unexpected kernel panics or crashes that may indicate an unpatched use‑after‑free scenario.

Generated by OpenCVE AI on September 19, 2026 at 07:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: printk: Fix possible console use-after-free When emitting a record via legacy printing, it is possible that a handover to another legacy printing context occurs. When a context has performed a handover, the console SRCU read lock is released and the pointer to the console struct might now be invalid. Therefore, after calling nbcon_legacy_emit_next_record() or console_emit_next_record(), it is necessary to check if a handover occurred _before_ further @con usage. Sashiko pointed out that console_flush_one_record() was not doing this. In console_flush_one_record(), after emitting a record, move the further usage of @con after the handover check.
Title printk: Fix possible console use-after-free
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:36.077Z

Reserved: 2026-09-17T16:02:15.087Z

Link: CVE-2026-93134

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:08.260

Modified: 2026-09-17T17:18:08.260

Link: CVE-2026-93134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:55Z

Weaknesses