Use-after-free in Linux kernel - CVE-2026-93288
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free.
The vulnerability exists due to failure to wait for an RCU grace period in nfnetlink_log per-network state when processing packets concurrently with network namespace teardown. A local user can trigger concurrent packet processing and network namespace teardown to trigger a use-after-free.