Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53294— mailbox: mailbox-test: don't free the reused channel

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel 4.4版本存在安全漏洞,该漏洞源于mailbox-test驱动中处理RX通道别名TX通道时释放重复通道,可能导致双重释放。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.13% · P3

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 8ea4484d0c2bb4e2152261943fa1a3522654b1c7< fc0089f82c3e36060c2c79156bc2018bfb16b56b affected
8ea4484d0c2bb4e2152261943fa1a3522654b1c7< 5d4f3d0f64f1016cb78b400a70b67df91fac99b5 affected
8ea4484d0c2bb4e2152261943fa1a3522654b1c7< c494a11da45ad7ec9b0ff216c3e3ace351193bb6 affected
8ea4484d0c2bb4e2152261943fa1a3522654b1c7< 3afca89fae501dbd7421e1777b5b8f033b1d98d0 affected
8ea4484d0c2bb4e2152261943fa1a3522654b1c7< 5c209299b0113e289e238fa5f2e8f00c59f76060 affected
8ea4484d0c2bb4e2152261943fa1a3522654b1c7< 82f6dcea46cf5de65c4ba7283f7c7b34de4a324d affected
8ea4484d0c2bb4e2152261943fa1a3522654b1c7< 240c71a2aea36a1a4210f911a1c32ea88777e8e4 affected
8ea4484d0c2bb4e2152261943fa1a3522654b1c7< 88ebadbf0deefdaccdab868b44ff70a0a257f473 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53294

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mailbox: mailbox-test: don't free the reused channel
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: don't free the reused channel The RX channel can be aliased to the TX channel if it has a different MMIO. This special case needs to be handled when freeing the channels otherwise a double-free occurs.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel 4.4版本存在安全漏洞,该漏洞源于mailbox-test驱动中处理RX通道别名TX通道时释放重复通道,可能导致双重释放。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 8ea4484d0c2bb4e2152261943fa1a3522654b1c7 ~ fc0089f82c3e36060c2c79156bc2018bfb16b56b -
Linux Linux 4.4 -

II. Public POCs for CVE-2026-53294

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53294

登录查看更多情报信息。

Patches & Fixes for CVE-2026-53294 (8)

Same Patch Batch · Linux · 2026-06-26 · 47 CVEs total

CVE-2026-53309 9.8 CRITICAL ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
CVE-2026-53281 8.8 HIGH iommu/vt-d: Avoid NULL pointer dereference or refcount corruption
CVE-2026-53322 8.8 HIGH vfio/pci: Clean up DMABUFs before disabling function
CVE-2026-53300 7.8 HIGH net: enetc: fix NTMP DMA use-after-free issue
CVE-2026-53290 7.8 HIGH drm/xe/eustall: Fix drm_dev_put called before stream disable in close
CVE-2026-53284 7.5 HIGH btrfs: only release the dirty pages io tree after successful writes
CVE-2026-53324 net: mana: Use pci_name() for debugfs directory naming
CVE-2026-53306 tty: hvc_iucv: fix off-by-one in number of supported devices
CVE-2026-53319 blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default()
CVE-2026-53321 io_uring/napi: cap busy_poll_to 10 msec
CVE-2026-53320 nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()
CVE-2026-53323 net: dsa: remove redundant netdev_lock_ops() from conduit ethtool ops
CVE-2026-53313 drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths
CVE-2026-53312 iommu/riscv: Remove overflows on the invalidation path
CVE-2026-53311 fuse: fix uninit-value in fuse_dentry_revalidate()
CVE-2026-53310 soc/tegra: cbb: Fix cross-fabric target timeout lookup
CVE-2026-53308 power: supply: max77705: Free allocated workqueue and fix removal order
CVE-2026-53307 pinctrl: pinconf-generic: Fully validate 'pinmux' property
CVE-2026-53305 usb: typec: ps883x: Fix Oops at unbind
CVE-2026-53303 f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show()

Showing top 20 of 47 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-53294

No comments yet


Leave a comment