Use-after-free in Linux kernel - CVE-2026-97943
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free in kernel page tables.
The vulnerability exists due to a use-after-free in cpa_collapse_large_pages when collapsing kernel page table entries. A local user can race a CPA collapse operation with a page-table walk to trigger a use-after-free in kernel page tables.
The affected collapse path is reached only when CPA_COLLAPSE is specified through set_memory_rox().