Use-after-free in Linux kernel - CVE-2026-98026
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free condition.
The vulnerability exists due to improper RCU synchronization in the bridge multicast mglist when deleting port groups concurrently with adjacent multicast-list traversal. A local user can cause a port group to be freed while br_multicast_list_adjacent() traverses the mglist to trigger a use-after-free condition.