Use-after-free in Linux kernel - CVE-2026-90431
Published: September 18, 2026
Vulnerability identifier: #VU151043
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90431
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the remoteproc crash-handler work when crash reporting races with remoteproc deletion. A local user can trigger concurrent crash reporting and remoteproc removal to cause a denial of service.
Affected software
Linux kernel
How to mitigate CVE-2026-90431
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/47de033918cd772146f7438aa04471c020b2dedc
- https://git.kernel.org/stable/c/50f232c26298923d39a48dc8e03d1732e5a5dcf1
- https://git.kernel.org/stable/c/61862ed651b2493573e6d2192d5640bc6616f5d0
- https://git.kernel.org/stable/c/69af36f1fb7d24d287662fef6b2093bcf847a9db
- https://git.kernel.org/stable/c/74ee3b2f5767447c57959994341e5b95f1079977
- https://git.kernel.org/stable/c/a31d9562eeec5c4103c202fc87651f6e7d3d0035
- https://git.kernel.org/stable/c/a8a62cb4d2f3fd6aa06e86f1711c62d2a4cf17d5
- https://git.kernel.org/stable/c/f15cde11298402f803d5dda9cb9f95eea3d2ca40