Use-after-free in Linux kernel - CVE-2026-89564
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to trigger a use-after-free.
The vulnerability exists due to improper socket reference management in IPv4 and IPv6 multicast forwarding paths when processing non-locally deliverable multicast packets. A remote attacker can send a non-locally deliverable multicast packet to trigger a use-after-free.
Exploitation requires the associated prefetched socket to be destroyed before the socket buffer is freed.