Use-after-free in Linux kernel - CVE-2026-93262
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in ppl_do_flush() when processing RAID5 PPL flushes. A local user can cause ppl_io_unit_finished() to free the io object while the loop continues accessing io->pending_flushes to trigger a use-after-free condition.
Affected software
How to mitigate CVE-2026-93262
External References
- https://git.kernel.org/stable/c/371f7a1b392edc8b7cf449cc7713179b588f2d0e
- https://git.kernel.org/stable/c/455b56209f9615c3902dcc398dd867abb5ade3ab
- https://git.kernel.org/stable/c/8914c3d40870f16429a326e97e4016bedc6ede4c
- https://git.kernel.org/stable/c/b5123bf667ac29ddd8106f9ca7cc01316513ae66
- https://git.kernel.org/stable/c/cf01f9413565e86673baf927291a088b6975692b
- https://git.kernel.org/stable/c/e7505842f1329ece90cb9ea0db87772aeca44052
- https://git.kernel.org/stable/c/e77c80670f2c2bf491da9b173931e1da4677c23a
- https://git.kernel.org/stable/c/fcf21df7d3c50c8ebeb0757df5d21b02dcae4218