Use-after-free in Linux kernel - CVE-2026-80850
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause a use-after-free condition.
The vulnerability exists due to use-after-free in TCP-AO information handling in tcp_ao_connect_init() when racing connect() with detaching a veth device from its VRF while sending TCP-AO segments. A local user can trigger access to stale tcp_ao_info data to cause a use-after-free condition.
TCP-AO must be configured.
Affected software
How to mitigate CVE-2026-80850
External References
- https://git.kernel.org/stable/c/284d7fd0eec8774bd6214921fbf525cf907c590e
- https://git.kernel.org/stable/c/594ba77210a1f065832211851a2d7e14d11fcbdb
- https://git.kernel.org/stable/c/70051a57786d5b23f059fbaf5c8241eca14d42ed
- https://git.kernel.org/stable/c/d17e88b6b60ff4ef64e0dd1444f935cb13dee1cd
- https://git.kernel.org/stable/c/ea30dc5267e367b8a5e1e06cc074f813bcbf18b2