Use-after-free in Linux kernel - CVE-2026-81006
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to access freed interface memory.
The vulnerability exists due to a use-after-free in the IPMI sysfs attribute cleanup logic when accessing the nr_msgs sysfs attribute after maintenance_mode file creation fails. A local user can access the stale nr_msgs sysfs attribute to access freed interface memory.