Use-after-free in Linux kernel - CVE-2026-80589
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a use-after-free in disk_release in the block layer when handling a probe failure for a disk that issued I/O before add_disk(). A remote attacker can trigger a failed disk initialization sequence that leaves a queue timeout timer pending to execute arbitrary code.
The issue can occur when a disk probe fails before the disk is added, including cases involving NVMe namespace initialization.
Affected software
How to mitigate CVE-2026-80589
External References
- https://git.kernel.org/stable/c/1a0ae4d502062a2759f2a92d12bdeab3c64c7372
- https://git.kernel.org/stable/c/26cb8ebbfaf713c82e142d08828d4d765057633b
- https://git.kernel.org/stable/c/6ae7364f68e6c7af6b6df4bbb14040b89e5975d0
- https://git.kernel.org/stable/c/6f06dbe5012c160e0dba418a5a9cb16c456ad46a
- https://git.kernel.org/stable/c/93d620519d71dfc6ee64b5baea74f1d85d4439fb
- https://git.kernel.org/stable/c/bb03b56d1d754908a37a160603be21769da423cf