Use-after-free in Linux kernel - CVE-2026-64344
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to use-after-free in the idmouse USB driver when release() races with disconnect(). A local user can trigger a device disconnect while the device file is being released to cause a denial of service or execute arbitrary code.
Exploitation requires a race condition involving device disconnection and file release in the idmouse driver.
Affected software
How to mitigate CVE-2026-64344
External References
- https://git.kernel.org/stable/c/31e75fed8f90cfea9f8285e7ed135b0e452bf872
- https://git.kernel.org/stable/c/54c2b7356b4aeea467f9fb13b85e9e036bc428cb
- https://git.kernel.org/stable/c/60fc5ef4ecea3e3d1fe556cecf53ddd13096ef09
- https://git.kernel.org/stable/c/8d53b14ad4ccbff6d306b3a39c812303f4a87d41
- https://git.kernel.org/stable/c/d0f61acb51a8c8f3fd41c303ddb7770cd83e7ed4
- https://git.kernel.org/stable/c/e88cff5fbaa629f3cab45c8b46f395d62c2eb515
- https://git.kernel.org/stable/c/f62622e947f82a3854a8502d09492ffbdeb252b4
- https://git.kernel.org/stable/c/ff002c153f9722caece3983cc23dc4d9d4652cb4