Use-after-free in Linux kernel - CVE-2026-90113
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to access freed memory.
The vulnerability exists due to a use-after-free in the netdevsim queue-to-NAPI mapping when resetting a receive queue and requesting queue information through Netlink. A local user can reset a queue through the queue_reset debugfs interface and request queue information through NETDEV_CMD_QUEUE_GET to access freed memory.