Use-after-free in Linux kernel - CVE-2026-89536
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a use-after-free condition.
The vulnerability exists due to a use-after-free in SUNRPC client TLS handshake handling when cancellation loses a race with completion of a TLS handshake callback. A local user can interrupt or time out a synchronous TLS handshake wait while the completion callback is in flight to cause a use-after-free condition.