Use-after-free in Linux kernel - CVE-2026-89690
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free.
The vulnerability exists due to use-after-free in the NFS server's NFSv4 compound operation buffer handling when an rpc_status netlink dump reads operation numbers concurrently with NFSv4 compound request completion. A local user can initiate concurrent operations to trigger a use-after-free.