Use-after-free in Linux kernel - CVE-2026-90041
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a use-after-free in the Sony HID driver's device list handling when handling probe failures for matching controllers. A remote attacker can cause a controller to remain linked in the device list after its driver state is freed to execute arbitrary code.