Use-after-free in Linux kernel - CVE-2026-80932
Published: September 13, 2026
Vulnerability details
The vulnerability allows a local user to cause a use-after-free condition.
The vulnerability exists due to improper workqueue synchronization in virtio_vsock_remove() when removing a virtio vsock device. A local user can trigger device removal while dependent work items are queued to cause a use-after-free condition.
The race involves tx_work, send_pkt_work, and rx_work.