Use-after-free in Linux kernel - CVE-2026-98036
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger a timer callback with references to freed memory.
The vulnerability exists due to improper lifecycle management in rhtab_map_update_elem() for BPF hash-map elements when updating a recycled map element. A local user can retain a map-value pointer after deleting its element, arm a timer through that pointer, and cause the element to be recycled.