Use-after-free in Linux kernel - CVE-2026-93819
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in the MediaTek PCIe controller driver's root bus removal routine when stopping and removing a root bus concurrently with rescan or hotplug operations triggered via sysfs. A local user can trigger concurrent rescan or hotplug operations via sysfs to cause a denial of service.