Use-after-free in Linux kernel - CVE-2026-80928
Published: September 13, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free of struct cred.
The vulnerability exists due to a use-after-free in smack_file_send_sigiotask() when accessing the credentials of another task during signal delivery. A local user can trigger the affected credential access during a concurrent credential change to trigger a use-after-free of struct cred.