Use-after-free in Linux kernel - CVE-2026-89942
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to use-after-free in the anonymous IIO buffer release function when releasing an anonymous buffer handle after its underlying IIO device has been removed. A local user can release an anonymous buffer handle holding the last reference to the underlying IIO device to compromise confidentiality, integrity, and availability.