Use-after-free in Linux kernel - CVE-2026-80521
Published: August 27, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code or cause a denial of service.
The vulnerability exists due to a use-after-free in unix_del_edge() and the af_unix garbage collector when processing concurrent socket edge updates and garbage collection. A local user can trigger concurrent send() and close() operations on crafted unix socket reference cycles to execute arbitrary code or cause a denial of service.
The issue occurs in a race window where a new edge becomes visible to garbage collection before its skb is queued, allowing a dead strongly connected component to be partially freed while stale scc_entry state remains reachable during a later GC walk.