Use-After-Free Vulnerability in Linux Kernel Affecting Request Key Authentication
CVE-2026-63823

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63823?

A use-after-free vulnerability exists within the Linux kernel's request_key_auth implementation. This issue arises during the instantiation and revocation process of authentication keys, where the function responsible for managing these keys fails to maintain the proper reference count on payloads. If an auth key is destroyed prematurely while still being referenced, it can lead to unintended use of freed memory, potentially allowing an attacker to exploit the situation. This vulnerability highlights the importance of correctly stabilizing the payload and revocation states before freeing resources.

Affected Version(s)

Linux b5f545c880a2a47947ba2118b2509644ab7a2969

Linux b5f545c880a2a47947ba2118b2509644ab7a2969 < 4982bfabce6b33b3c9eddb4fb900fe5568b7cf91

Linux b5f545c880a2a47947ba2118b2509644ab7a2969 < 708709c65a1832a99b0eef8ae46e343ddaca3d06

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.