Use-after-free in Linux kernel - CVE-2026-89635

 

Use-after-free in Linux kernel - CVE-2026-89635

Published: September 12, 2026


Vulnerability identifier: #VU149164
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89635
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to a use-after-free in ksmbd durable-handle oplock reconnection handling when reconnecting a durable file handle. A remote user can reconnect one durable handle after two sessions holding durable handles for the same file have disconnected, then trigger processing of the other handle's application instance ID to cause a denial of service.

Exploitation requires durable-v2 handles with RH leases under distinct AppInstanceIds on the same file.


Affected software

Linux kernel

How to mitigate CVE-2026-89635

Install security update from vendor's repository.


External References

Related Security Bulletins