Use-after-free in Linux kernel - CVE-2026-72489
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in nvec_rx_completed() when handling an incomplete RX transfer. A local user can trigger an incomplete RX transfer to execute arbitrary code.
The freed message slot may be reallocated by a concurrent call to nvec_msg_alloc() before the code reads the message type byte.
Affected software
Ubuntu
linux-nvidia-tegra (Ubuntu package)
How to mitigate CVE-2026-72489
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1035.38
External References
- https://git.kernel.org/stable/c/08626fcfe12308ca3f8b22c538ba7dee0b2dce7a
- https://git.kernel.org/stable/c/26813881181deb3a32fbb59eadb2599cbe8423f6
- https://git.kernel.org/stable/c/5de04caa46b635e180cecbd164e333eca535db94
- https://git.kernel.org/stable/c/6b2ea886ebdae44a2394029844a4e78f58e1587d
- https://git.kernel.org/stable/c/9f7fe4165a1f1014bdadc8e744c0fd3c2d8c0b89
- https://git.kernel.org/stable/c/a37625c7b688fcf68a54263528eccbabfd7fa17a
- https://git.kernel.org/stable/c/bb3d592c7d6c4ec8ac6640c690ca13298e7e8e90
- https://git.kernel.org/stable/c/f19a5bc059051143c489dd6f79a0f9c3bfd13aea