CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-68318

highCVSS 7.8covered by 2 sourcesfirst seen 2026-08-10
In the Linux kernel, the following vulnerability has been resolved: pds_core: fix use-after-free on workqueue during remove In pdsc_remove(), the workqueue is destroyed before pdsc_teardown() is called. This ordering allows two paths to queue work on the destroyed workqueue: 1. If pdsc_teardown() -> pdsc_devcmd_reset() times out, the error path in pdsc_devcmd_locked() queues health_work. 2. A NotifyQ event can trigger the ISR and queue work before free_irq() is called in pdsc_teardown(). Fix by moving destroy_workqueue() after pdsc_teardown() so the workqueue outlives every queuer; destroy_workqueue() then flushes any work still pending. Draining the queued work also requires ordering the teardown so the resources that work touches are freed last: - In pdsc_qcq_free(), after freeing the interrupt, cancel_work_sync() the queue's work and only then clear qcq->intx, so pdsc_process_adminq()'s read of qcq->intx for interrupt-credit return cannot race with the clear. - Free adminqcq before notifyqcq: the shared adminq ISR is released when adminqcq is freed, and the adminq work accesses notifyqcq, so both must be stopped before notifyqcq is freed.

CSIRTS triage

What
The pds_core driver has a use-after-free vulnerability in workqueue handling during device removal.
Who is affected
Linux systems with Pensando DMA Security core driver.
Urgency
High priority; CVSS 7.8 and use-after-free during removal poses serious risk.
Action
Apply kernel patch fixing workqueue cleanup synchronization in pds_core remove.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-68318

Get an email if CVE-2026-68318 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-68318

CVE.org record

Embed the live status

CVE-2026-68318 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-68318 status](https://www.csirts.com/badge/CVE-2026-68318)](https://www.csirts.com/cve/CVE-2026-68318)