Use-after-free in Linux kernel - CVE-2026-97986
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free.
The vulnerability exists due to a race condition in virtinput_remove() and virtinput_recv_events() when a virtio input callback runs during input-device unregistration. A local user can cause a callback that passed the ready-state check to access vi->idev after it is freed to trigger a use-after-free.
The lifetime issue is not protected for sleepable callbacks on transports other than PCI and MMIO.