Use-after-free in Linux kernel - CVE-2026-45936
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local attacker to cause a denial of service or corrupt memory.
The vulnerability exists due to use-after-free in the goldfish power supply driver when handling interrupts during device removal or initialization. A local attacker can trigger a race condition to cause a denial of service or corrupt memory.
An interrupt may fire after the power_supply handle has been freed or before it has been initialized.
How to mitigate CVE-2026-45936
Sources
- https://git.kernel.org/stable/c/0b29ffe4090a3fc7a7649de20e1eb1e53adddac7
- https://git.kernel.org/stable/c/33751e28842bf5aee5ef7b2b8d5e456a069095cb
- https://git.kernel.org/stable/c/4350505e82b4f972ddb788e1c712c557c38859d0
- https://git.kernel.org/stable/c/589d4fe56713c6344cd9f8939f9c7621c85f0966
- https://git.kernel.org/stable/c/77ea437faa4c06362e3ecfd2d7264eaa7ac1e82c
- https://git.kernel.org/stable/c/8c89aade8335e26a6a7dcda18992d15f51943927
- https://git.kernel.org/stable/c/b2ce982e2e0c888dc55c888ad0e20ea04daf2e6b
- https://git.kernel.org/stable/c/bad8b61eb5059acd88349680e47839342dc89e94