Use-after-free in Linux kernel - CVE-2026-68266
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the xe dma-buf imported buffer object handling when tearing down imported buffer objects after dma_buf_dynamic_attach() or buffer object creation fails. A local user can trigger creation of a crafted imported dma-buf buffer object to cause a denial of service.
The issue can be reached on failure paths where the buffer object already references the exporter's reservation object and that reservation object is later accessed asynchronously during delayed deletion.
Affected software
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
kernel (Red Hat package)
linux (Debian package)
How to mitigate CVE-2026-68266
kernel (Red Hat package) - update to 5.14.0-687.52.1.el9_8
linux (Debian package) - update to 6.12.105-1