CVE-2026-63930
Published Jul 19, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: iio: buffer: hw-consumer: fix use-after-free in error path In the err_put_buffers cleanup path of iio_hw_consumer_alloc(), the code was using list_for_each_entry() to iterate through buffers while calling iio_buffer_put() which can free the current buffer if refcount drops to 0. The list_for_each_entry() loop macro then evaluates buf->head.next to continue iteration, accessing the freed buffer. Fix this by using list_for_each_entry_safe().
Is your site exposed to CVE-2026-63930?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/29783e6b6ec0b7152a15e53a063f17537e81177d
https://git.kernel.org/stable/c/2ff615fc455acda5425c4900160cbe11cfea4449
https://git.kernel.org/stable/c/6f5ed4f2c7c83f33344e0ba179f72a12e5dad4a4
https://git.kernel.org/stable/c/9319c94f63ed10723afd738d79f5617daba87cc8
https://git.kernel.org/stable/c/a3763ae33476328cf8d661742deb9daec78eac96
https://git.kernel.org/stable/c/b71893c57730809c222766e5718bb33610f11963
https://git.kernel.org/stable/c/d2759d49860b9a39b5cde2fb88e4b822ddf5f58f
https://git.kernel.org/stable/c/e965627f0d442bfcae3f496c90cb653fb0917a61
Frequently Asked Questions
What is CVE-2026-63930? +
In the Linux kernel, the following vulnerability has been resolved:
iio: buffer: hw-consumer: fix use-after-free in error path
In the err_put_buffers cleanup path of iio_hw_consumer_alloc(), the code
was using list_for_each_entry() to iterate through buffers while calling
iio_buffer_put() which can free the current buffer if refcount drops to 0.
The list_for_each_entry() loop macro then evaluates buf->head.next to
continue iteration, accessing the freed buffer.
Fix this by using list_for_each_entry_safe().
How do I check if I'm vulnerable to CVE-2026-63930? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.