Use-after-free in Linux kernel - CVE-2026-90277
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free condition.
The vulnerability exists due to a use-after-free in llbitmap_create() when bitmap creation fails while bitmap statistics are being collected. A local user can trigger a failed bitmap creation while a mutex-protected reader accesses bitmap statistics to trigger a use-after-free condition.