CVE-2026-68152
Received Received - Intake

Use-After-Free in Linux Kernel AMT Subsystem

Vulnerability report for CVE-2026-68152, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: amt: fix use-after-free in AMT delayed works When an AMT device is removed, pending delayed works can still access the freed amt_dev structure, which may result in kernel crashes or memory corruption. amt_dev_stop() cancels req_wq and discovery_wq with cancel_delayed_work_sync(), but these works can be scheduled again from event_wq after the cancellation. This allows delayed works to access the freed amt_dev structure after the netdev has been released. The following is a simple race scenario: CPU0 CPU1 amt_dev_stop() cancel_delayed_work_sync() amt_event_work() mod_delayed_work(req_wq) free netdev req_wq accesses freed amt_dev Use disable_delayed_work_sync() in amt_dev_stop() to prevent req_wq and discovery_wq from being queued again and wait for running work items to complete. The delayed works are disabled after initialization in amt_newlink() and enabled only when the device is successfully opened. This keeps the delayed work lifecycle synchronized with the lifetime of the AMT device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a use-after-free flaw in the Linux kernel's AMT (Active Management Technology) delayed works. When an AMT device is removed, pending delayed works may still access the freed amt_dev structure, causing kernel crashes or memory corruption. The issue occurs because delayed works can be rescheduled after cancellation, leading to access of freed memory.

Detection Guidance

This vulnerability involves a use-after-free in the Linux kernel's AMT delayed works. Detection requires checking kernel logs for crashes or memory corruption related to AMT devices. Monitor logs with dmesg or journalctl for kernel oops messages or warnings about freed memory access.

Impact Analysis

This vulnerability can cause system instability, including kernel crashes or memory corruption, potentially leading to denial-of-service conditions. Systems using AMT devices may experience unexpected reboots or data corruption if exploited.

Mitigation Strategies

Apply the kernel patch that fixes the use-after-free in AMT delayed works. Update to a patched Linux kernel version where disable_delayed_work_sync() is used in amt_dev_stop() to prevent delayed works from accessing freed memory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68152. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart