{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.10-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  idpf: fix double free and use-after-free in aux device error paths  When auxiliary_device_add() fails in idpf_plug_vport_aux_dev() or idpf_plug_core_aux_dev(), the err_aux_dev_add label calls auxiliary_device_uninit() and falls through to err_aux_dev_init.  The uninit call will trigger put_device(), which invokes the release callback (idpf_vport_adev_release / idpf_core_adev_release) that frees iadev.  The fall-through then reads adev-\u003eid from the freed iadev for ida_free() and double-frees iadev with kfree().  Free the IDA slot and clear the back-pointer before uninit, while adev is still valid, then return immediately.  Commit 65637c3a1811 (\"idpf: fix UAF in RDMA core aux dev deinitialization\") fixed the same use-after-free in the matching unplug path in this file but missed both probe error paths.",
  "id": "DEBIAN-CVE-2026-53286",
  "modified": "2026-09-14T16:47:34.054949900Z",
  "published": "2026-06-26T20:17:21.353Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-53286"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-53286"
  ]
}