Use-after-free in Linux kernel - CVE-2026-90429
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free caused by improper synchronization in the tegra241 CMDQV error interrupt handler and VINTF lifecycle management when a user VINTF is concurrently torn down while an error interrupt is handled. A local user can trigger a race between VINTF teardown and error-interrupt handling to cause a denial of service.