Use-after-free in Linux kernel - CVE-2026-90121
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause CPUs to retain associations with freed memory.
The vulnerability exists due to use-after-free in the GICv5 IRS affinity state when IRS initialization fails or an IRS is torn down. A local user can trigger IRS initialization failure or teardown to cause CPUs to retain associations with freed memory.