Use-after-free in Linux kernel - CVE-2026-89623
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free.
The vulnerability exists due to improper device I/O shutdown in the MCP2221 HID driver cleanup callback when incoming HID reports race with hardware teardown during probe failure or device removal. A local user can trigger the race condition to trigger a use-after-free.