Use-after-free in Linux kernel - CVE-2026-89669
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to a use-after-free in copy-notify state initialization when racing a crafted OFFLOAD_CANCEL request against COPY_NOTIFY processing. A remote attacker can send a crafted OFFLOAD_CANCEL request to trigger a use-after-free condition.
Exploitation requires a matching client ID and a guessable state object ID.