Use-after-free in Linux kernel - CVE-2026-89643
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to a use-after-free in audit_del_rule() when fsnotify automatically removes mixed AUDIT_DIR and AUDIT_EXE rules that share an audit tree. A local privileged user can trigger fsnotify autoremove events to cause a denial of service.