Use-after-free in Linux kernel - CVE-2026-97562

 

Use-after-free in Linux kernel - CVE-2026-97562

Published: September 28, 2026


Vulnerability identifier: #VU152651
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97562
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in the SMB client DFS superblock lookup callback when handling DFS automounts during concurrent expiry. A remote attacker can trigger concurrent DFS automount expiry while the superblock is in use to compromise confidentiality, integrity, and availability.

User interaction is required.


Affected software

Linux kernel

How to mitigate CVE-2026-97562

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins