---
id: CVE-2026-53157
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: phonet: free phonet_device after RCU grace period

  phonet_device_destroy() removes a phonet_device from the per-net device
  list with list_del_rcu(), but frees it i…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: phonet: free phonet_device after RCU grace period

  phonet_device_destroy() removes a phonet_device from the per-net device
  list with list_del_rcu(), but frees it i…
severity: none
published: '2026-06-25'
updated: '2026-07-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53157'
references:
  - url: 'https://git.kernel.org/stable/c/09c9b92c2010481160245244ea8fa1d06d5d4ae0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2ec8011cce0cd0fc7a5068585d867fc08d508578'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/52b8f5ef82c886f7cd24617915e4b1579ddfd001'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6cd7067d6e4b0b2033ba2f918ecbd54dc2af3763'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/71de0177b28da751f407581a4515cf4d762f6296'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bd2ab4d800fc26814d89328d87b5f97ef6aa906a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bff309ea51f1395c1ef8be8b75ce62d28a319113'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d59794337ea496042288c7c68356d9b9ca7f46a9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00126
epssPercentile: 0.01921
ingestedAt: '2026-07-04T12:56:09.630Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: phonet: free phonet_device after RCU grace period

phonet_device_destroy() removes a phonet_device from the per-net device
list with list_del_rcu(), but frees it immediately. RCU readers walking
the same list can still hold a pointer to the object after it has been
removed, leading to a slab-use-after-free.

Use kfree_rcu(), matching the lifetime rule already used by
phonet_address_del() for the same object type.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
