SB20260816462 - Use-after-free in Linux kernel locking
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-72069)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in rt_spin_unlock(), rt_read_unlock(), and rt_write_unlock() when releasing RCU protection before completing unlock operations. A local user can trigger concurrent lock and RCU operations to execute arbitrary code.
The issue affects the RT spinlock and rwlock substitutions where unlock handling does not preserve the expected non-RT RCU protection semantics.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1f0d56d3f1e88f20f6e46109402f8c15d59bac37
- https://git.kernel.org/stable/c/3cfaac77b3c32ac3940df28866de263c3f45d24c
- https://git.kernel.org/stable/c/633cadbc0b8323f5cc140a285d2432089dbb534e
- https://git.kernel.org/stable/c/83f9fb561c1c3917e19f95523dd933c7d30291aa
- https://git.kernel.org/stable/c/89038cc87d80c77e7aa6f42a64b2573b74af339f