Use-after-free in Linux kernel - CVE-2026-98006
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free.
The vulnerability exists due to a use-after-free in the ALSA caiaq USB driver's ep1_in_urb and midi_out_urb handling when processing a command timeout after a submitted URB is unlinked by the dummy HCD driver. A local user can trigger the affected initialization failure to trigger a use-after-free.