Use-after-free in Linux kernel - CVE-2026-92511
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free condition.
The vulnerability exists due to a use-after-free in ib_destroy_cq_user() when accessing a completion queue through the netlink path during its destruction. A local user can access a completion queue through netlink while it is being destroyed to trigger a use-after-free condition.
Affected software
How to mitigate CVE-2026-92511
External References
- https://git.kernel.org/stable/c/197c262dbf94c0f7ab7ac54b66f892ce9f343232
- https://git.kernel.org/stable/c/253c2ed71a532c70fa0e64317ceb02bb1a50c84c
- https://git.kernel.org/stable/c/3481bec4dfc4aee24ffea5a547ee95b70b67d9d5
- https://git.kernel.org/stable/c/42f7a0c7a94003059540cce448acabfa62ad119d
- https://git.kernel.org/stable/c/8a72a6aad84b3928dbb5e564bff1f56a7ec222ae
- https://git.kernel.org/stable/c/b85a148731eceffacb6a030950187d785175607f