Use-after-free in Linux kernel - CVE-2026-93131
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to access freed memory.
The vulnerability exists due to a use-after-free race condition in the Dell privacy WMI driver when accessing the features_present field without holding the list mutex. A local user can trigger concurrent access to the field while the associated privacy data is freed to access freed memory.
Affected software
How to mitigate CVE-2026-93131
External References
- https://git.kernel.org/stable/c/239ae86b7c97341f49d2ba32037ee3ddbaf0f1ab
- https://git.kernel.org/stable/c/2d2108685a491b369f95774d0a7579d6e5287215
- https://git.kernel.org/stable/c/9f860050c3d17ff8499d3998f7534d306c3da50a
- https://git.kernel.org/stable/c/a22beeb90475b5f71a477564eecf764b24f47277
- https://git.kernel.org/stable/c/ca9338dbc64759b30741b12017c050b33c94dfa2
- https://git.kernel.org/stable/c/ef59ff891adf9bd696917f71f841fdb23c245790
- https://git.kernel.org/stable/c/f3c4532f6dac8fb5504d342e2a15e6353e5eb56e