{"id":"CVE-2026-68423","summary":"mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy()\n\nmtd_concat_destroy() frees item-\u003econcat so calling\nmtd_virt_concat_put_mtd_devices(item-\u003econcat) after that leads to a\nuse-after-free.\n\nFix it by moving mtd_virt_concat_put_mtd_devices() before\nmtd_concat_destroy().","modified":"2026-08-12T04:24:33.048569657Z","published":"2026-08-10T12:04:43.942Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68423.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/4b45d7836b9526b8776af5f29219615be9417230"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d36520e5da8bf87265b334def0daaadf3603cc62"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68423.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68423"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"43db6366fc2de02050e66389f5628d3fdc9af10a"},{"fixed":"d36520e5da8bf87265b334def0daaadf3603cc62"},{"fixed":"4b45d7836b9526b8776af5f29219615be9417230"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68423.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.1.0"},{"fixed":"7.1.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68423.json"}}],"schema_version":"1.9.0"}