Use-after-free in Linux kernel - CVE-2026-89893
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to read or modify sensitive information and cause a denial of service.
The vulnerability exists due to a use-after-free in the NetUP CI status work handling in drivers/media/pci/cx23885/cimax2.c when tearing down a NetUP CI device while CI status work is pending or running. A local user can trigger device teardown while the queued status worker can still access freed state to read or modify sensitive information and cause a denial of service.
Affected software
How to mitigate CVE-2026-89893
External References
- https://git.kernel.org/stable/c/140ecbcbf978fbe60f83f8d4f8b1199029a5c763
- https://git.kernel.org/stable/c/4e143d662ca94888b494b2427fc9e34494eb933a
- https://git.kernel.org/stable/c/5deec890ecfa04d21cfa9bb9a2fe5e9dc98db5c5
- https://git.kernel.org/stable/c/99cd62b9b1c818d6d01a87be9a8e5796314150a2
- https://git.kernel.org/stable/c/aaf76794b870b0f391eff339252a2e2e22f33a4a
- https://git.kernel.org/stable/c/bf3f49273d5bf6acbdad18ff44c01ffcf7a7a146
- https://git.kernel.org/stable/c/ec82b0cf7f75fd95802592dcc9560fc7f529bba4
- https://git.kernel.org/stable/c/f7ff5adb63c1b277565afa54ccc0924d841b4a52