Use-after-free in Linux kernel - CVE-2026-80572
Published: August 27, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in the byd driver timer callback handling in drivers/input/mouse/byd.c when disconnecting the device while timer callbacks are running or being re-armed. A local user can trigger a race condition to execute arbitrary code.
The issue arises because the callback can dereference freed private data and its psmouse pointer during driver disconnect.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-80572
linux (Debian package) - update to 6.12.107-1