Use-after-free in Linux kernel - CVE-2026-98017
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to a use-after-free in the Linux kernel traffic-control queueing discipline creation path when processing an RTM_NEWQDISC request with an invalid TCA_RATE attribute after binding a populated shared ingress block. A local user can send a crafted RTM_NEWQDISC request to cause memory corruption.