Use-after-free in Linux kernel - CVE-2026-89892
Published: September 17, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to trigger a use-after-free.
The vulnerability exists due to improper device list management in the em28xx audio-only extension registration path when connecting and disconnecting a dual-TS board. An attacker with physical access can connect and disconnect a dual-TS board to trigger a use-after-free.
The condition affects audio-only paths on dual-TS boards.
Affected software
How to mitigate CVE-2026-89892
External References
- https://git.kernel.org/stable/c/0da1e627f4fc9d0e947fdae90913042120878923
- https://git.kernel.org/stable/c/1abe9524dec0fd26e9ceb8d586034d6f68dd8273
- https://git.kernel.org/stable/c/4666197ca4f7d80cd3b0292054fe45d76be9ba04
- https://git.kernel.org/stable/c/4e11c45dfdc72ab656067b1df8fcebaf52fd4715
- https://git.kernel.org/stable/c/95f76f51937fdfb0fc1e14cae606b1ef574a56f3
- https://git.kernel.org/stable/c/d06067ee32620f272cfb80c7bc7c572ad4e74724
- https://git.kernel.org/stable/c/f8d7e77d9c621b42a191c67a9b37bec23dc1d555
- https://git.kernel.org/stable/c/f9322ac9f862961d7f377b87ec26c8565af7e073