Use-after-free in Linux kernel - CVE-2026-90334
Published: September 18, 2026
Vulnerability identifier: #VU151155
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90334
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a use-after-free.
The vulnerability exists due to use-after-free in tty_cdev_add() when handling a cdev_add() failure. A local user can trigger tty device unregistration after cdev_add() fails to cause a use-after-free.
Affected software
Linux kernel
How to mitigate CVE-2026-90334
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/33a44333a9dfda044b0e233399b12ead7f8a90ae
- https://git.kernel.org/stable/c/4f6bd79bb7e55095f09bec9b4eb6c09df1306116
- https://git.kernel.org/stable/c/5c5a795bf6248fe96f96dd9fd79d66bbb4a92077
- https://git.kernel.org/stable/c/6645856f0df3aeecd45519cb611415b4b89c2223
- https://git.kernel.org/stable/c/a83fcddf3c75d004f12aa13555bb73da19fb75a9
- https://git.kernel.org/stable/c/d331c63570af61ef7aaf516b64a8d6f47518a3a4
- https://git.kernel.org/stable/c/e9e64dd02fd68776afda00777591eca0c3984285
- https://git.kernel.org/stable/c/fb1de260033c215dba438973d82b48562bdc86bb