Use-after-free in Linux kernel - CVE-2026-97475
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local privileged user to trigger a use-after-free.
The vulnerability exists due to failure to unregister thermal cooling devices in the Tegra SoCTherm driver when the platform driver is removed. A local privileged user can cause the driver to be removed and trigger use of a stale thermal framework reference to trigger a use-after-free.
The stale cooling-device references retain devdata pointers to memory freed during platform-device cleanup.