CVE-2026-68181: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: mei: bus: access mei_device under device_lock on cleanup Fix couple of problems in mei_cl_bus_dev_release(): mei_cl_flush_queues() is running without lock. bus->file_list access after mei_dev_bus_put(bus) can become a use-after-free if this was the last reference to bus. Protect queues cleanup and WARN traversal by device lock there to avoid the concurrent access problems. Move WARN traversal before mei_dev_bus_put(bus). This file uses bus variable name for mei_device, adjust code of mei_cl_bus_dev_release() to use bus variable too.

Affected products

  • Linux Linux: from 6.1.149, before 6.1.184 (fixed in 6.1.184); from 6.6.103, before 6.6.148 (fixed in 6.6.148); from 6.12.43, before 6.12.101 (fixed in 6.12.101); from 6.15.11, before 6.16 (fixed in 6.16); from 6.16.2, before 6.17 (fixed in 6.17); from 6.17, before 6.18.42 (fixed in 6.18.42); …

Published 2026-08-10. Last modified 2026-08-23.