Medium severity5.5NVD Advisory· Published Jun 26, 2026· Updated Jul 8, 2026
CVE-2026-53297
CVE-2026-53297
Description
In the Linux kernel, the following vulnerability has been resolved:
net: mana: Guard mana_remove against double invocation
If PM resume fails (e.g., mana_attach() returns an error), mana_probe() calls mana_remove(), which tears down the device and sets gd->gdma_context = NULL and gd->driver_data = NULL.
However, a failed resume callback does not automatically unbind the driver. When the device is eventually unbound, mana_remove() is invoked a second time. Without a NULL check, it dereferences gc->dev with gc == NULL, causing a kernel panic.
Add an early return if gdma_context or driver_data is NULL so the second invocation is harmless. Move the dev = gc->dev assignment after the guard so it cannot dereference NULL.
Affected products
4Patches
Vulnerability mechanics
References
3News mentions
2- Linux Kernel: 25 Vulnerabilities Affecting Networking, Graphics, and Memory Management Disclosed TogetherVypr Intelligence · Jun 27, 2026
- Linux Kernel: Batch of 11 Vulnerabilities Affecting Networking, Graphics, and Crypto ResolvedVypr Intelligence · Jun 27, 2026