Use-after-free in Linux kernel - CVE-2026-89922
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information, modify data, or cause a denial of service.
The vulnerability exists due to improper synchronization in __import_wp_info() when importing watchpoint data during a concurrent memslot update. A local user can initiate watchpoint data import while a concurrent memslot update occurs to disclose sensitive information, modify data, or cause a denial of service.
Affected software
How to mitigate CVE-2026-89922
External References
- https://git.kernel.org/stable/c/4c05bf21d1806853e662cc19e744736a3408f155
- https://git.kernel.org/stable/c/6830fbc3724bf49c142aae69a4694f115fa9cedd
- https://git.kernel.org/stable/c/76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03
- https://git.kernel.org/stable/c/a4e482def8533ebace517d9f67f1465841b1f982
- https://git.kernel.org/stable/c/cc710ee45395efb4937e042960f791d33924e5f6
- https://git.kernel.org/stable/c/f8e3a9997d5ecd56ebe4b262ff424516c068fecb