Use-after-free in Linux kernel - CVE-2026-80849
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to access freed memory.
The vulnerability exists due to use-after-free in current_key handling in the TCP Authentication Option (TCP-AO) code when processing inbound TCP-AO traffic during a socket reconnect to a different peer. A local user can race inbound TCP-AO processing with reconnecting a socket to another peer to access freed memory.
Affected software
How to mitigate CVE-2026-80849
External References
- https://git.kernel.org/stable/c/2857dcbd03cf3354af0fba1b65c6a260fb43811a
- https://git.kernel.org/stable/c/73fde8fe4469f4ed8f0afcc0b9d6413002a9e6b3
- https://git.kernel.org/stable/c/84a93b4e012587d0a4a84ffb23ec6da18e9d85f9
- https://git.kernel.org/stable/c/da4471557f279d0f56605158a625bb6e49ef7d41
- https://git.kernel.org/stable/c/e54ad693eddb40c595add013f545354c538e325b