Double free in Linux kernel - CVE-2026-93827
Published: September 25, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to trigger a double-free.
The vulnerability exists due to a double free in the virtio-fs queue setup and probe cleanup paths when probing a virtio-fs device that advertises more request queues than the transport provides. An attacker with physical access can present a malformed virtio-fs device to cause virtio_find_vqs() to fail during extra queue setup and trigger a double-free.