Use-after-free in Linux kernel - CVE-2026-98033
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free.
The vulnerability exists due to improper preservation of map identity in BPF verifier callback frame constructors when invoking timer callbacks on nested inner maps. A local user can pair a timer from a second inner map with a first inner map and free the first map to trigger a use-after-free.