Use-after-free in Linux kernel - CVE-2026-80572

 

Use-after-free in Linux kernel - CVE-2026-80572

Published: August 27, 2026


Vulnerability identifier: #VU145919
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80572
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to a use-after-free in the byd driver timer callback handling in drivers/input/mouse/byd.c when disconnecting the device while timer callbacks are running or being re-armed. A local user can trigger a race condition to execute arbitrary code.

The issue arises because the callback can dereference freed private data and its psmouse pointer during driver disconnect.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-80572

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.107-1

External References

Related Security Bulletins