Use-after-free in Linux kernel - CVE-2026-89452
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in msm_iommu_probe() in the MSM IOMMU driver when IOMMU device sysfs setup or registration fails. A local user can trigger a failed probe to leave a dangling entry in qcom_iommu_devices to cause a denial of service.
A later traversal of qcom_iommu_devices is required to dereference the dangling list entry.