CVE-2026-53299 is a vulnerability in Linux Kernel
Published on June 26, 2026
net: airoha: Move ndesc initialization at end of airoha_qdma_init_tx()
In the Linux kernel, the following vulnerability has been resolved:
net: airoha: Move ndesc initialization at end of airoha_qdma_init_tx()
If queue entry list allocation fails in airoha_qdma_init_tx_queue routine,
airoha_qdma_cleanup_tx_queue() will trigger a NULL pointer dereference
accessing the queue entry array. The issue is due to the early ndesc
initialization in airoha_qdma_init_tx_queue(). Fix the issue moving ndesc
initialization at end of airoha_qdma_init_tx routine.
Products Associated with CVE-2026-53299
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version ad02cb61c52cae5afa3e2de6adbb49ad884c26e9 and below 90619fdedfb9cc8a80f217d882ee7a84d3703e72 is affected.
- Version 3f47e67dff1f7266e112c50313d63824f6f17102 and below ece31f9dae0c3cd3277e66667e7b8ab2577cf34a is affected.
- Version 3f47e67dff1f7266e112c50313d63824f6f17102 and below f329924bb49458c65297f1361f545816a5b90998 is affected.
- Version 6.19 is affected.
- Before 6.19 is unaffected.
- Version 7.0.10, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.