Use-after-free in Linux kernel - CVE-2026-90029
Published: September 16, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to trigger a use-after-free.
The vulnerability exists due to a use-after-free in the Realtek USB card reader driver's suspend timer handling when disconnecting a USB device while the timer callback is running. An attacker with physical access can disconnect the device while the callback rearms the timer to trigger a use-after-free.
The issue applies to configurations with Realtek automatic power management enabled.