Use-after-free in Linux kernel - CVE-2026-90092
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to a race condition in l2cap_sock_new_connection_cb when handling new L2CAP connections during parent L2CAP channel teardown. A remote attacker can initiate a new L2CAP connection while a parent socket is being torn down to trigger a use-after-free condition.
Affected software
How to mitigate CVE-2026-90092
External References
- https://git.kernel.org/stable/c/2a3a27aaf19bf069720e024ce6fde54e6bf80df9
- https://git.kernel.org/stable/c/491e4c60017969b053888029998d2a61f298986a
- https://git.kernel.org/stable/c/87276dc15b559d32757a43b4415c8445fbae06c4
- https://git.kernel.org/stable/c/bf61a65c6093970e3b50031c4b79ebf3bd411eba
- https://git.kernel.org/stable/c/c47339e169bf4a0a4cfabb91351471f67744c2bc
- https://git.kernel.org/stable/c/d4bfa78fd67929b62b02013c107973e0c5b7aa9a