Use-after-free in Linux kernel - CVE-2026-90022
Published: September 16, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code, disclose sensitive information, or cause a denial of service.
The vulnerability exists due to use-after-free in the f_midi2 string attribute show path when concurrently reading and writing string attributes. A local user can concurrently access and modify string attributes to execute arbitrary code, disclose sensitive information, or cause a denial of service.
Affected software
How to mitigate CVE-2026-90022
External References
- https://git.kernel.org/stable/c/49fab5e1bdb205c36c965d0e9677bc40d282d3a2
- https://git.kernel.org/stable/c/d11f3300b39e2daad2f0d9d66ddcc39a156cb594
- https://git.kernel.org/stable/c/e89e30f0b5d3004fe5955250bd8b04f3733e32ce
- https://git.kernel.org/stable/c/f9bdf4c4f6410a1dfafafa383a0e21069372657f
- https://git.kernel.org/stable/c/fed0aa7c6eaedc6c0d4e362fc91724aa47be4a7b