Use-after-free in Linux kernel - CVE-2026-89488
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to trigger a slab use-after-free.
The vulnerability exists due to a race condition leading to use-after-free in the Open vSwitch conntrack limit state when tearing down a network namespace while packet processing accesses the state. A local user can tear down a network namespace while packet processing accesses CT limit state to trigger a slab use-after-free.
Exploitation requires a user and network namespace.