Use-after-free in Linux kernel - CVE-2026-31769
Published: May 2, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in gpib IO ioctl handlers when processing concurrent ioctl operations on the same descriptor. A local user can trigger IBRD, IBWRT, IBCMD, or IBWAIT while concurrently issuing IBCLOSEDEV to cause a denial of service.
The issue arises because the descriptor can become unprotected after the mutex is released, and multiple threads can operate on the same descriptor concurrently.