Use-after-free in Linux kernel - CVE-2026-89938

 

Use-after-free in Linux kernel - CVE-2026-89938

Published: September 17, 2026


Vulnerability identifier: #VU150345
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89938
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a use-after-free in the Atlas sensor driver's IRQ work handling when a pending irq_work executes after device removal. A local user can cause pending IRQ work to execute after device removal to compromise confidentiality, integrity, and availability.

Exploitation requires an enabled IIO buffer.


Affected software

Linux kernel

How to mitigate CVE-2026-89938

Install security update from vendor's repository.


External References

Related Security Bulletins