Use-after-free in Linux kernel - CVE-2026-89942

 

Use-after-free in Linux kernel - CVE-2026-89942

Published: September 17, 2026


Vulnerability identifier: #VU150349
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89942
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in the anonymous IIO buffer release function when releasing an anonymous buffer handle after its underlying IIO device has been removed. A local user can release an anonymous buffer handle holding the last reference to the underlying IIO device to compromise confidentiality, integrity, and availability.


Affected software

Linux kernel

How to mitigate CVE-2026-89942

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins