Use-after-free in Linux kernel - CVE-2026-89463
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to use-after-free in the ucs1002 health_poll delayed work when unbinding the ucs1002 driver while health polling work is queued. A local privileged user can cause the driver to be unbound while health polling work is queued to cause a denial of service.
The delayed work can reschedule itself while the chip reports a bad-health condition.