Use-after-free in Linux kernel - CVE-2026-89737
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a use-after-free condition.
The vulnerability exists due to failure to synchronize work item teardown in tbt_altmode_remove() in the Thunderbolt Type-C alternate mode driver when removing a Thunderbolt alternate mode while tbt->work is pending. A local user can trigger alternate mode removal while the pending work item can dereference dropped plug and cable references to cause a use-after-free condition.