Use-After-Free Vulnerability in Linux Kernel Affecting RapidIO Interface
CVE-2026-89742

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89742?

A use-after-free vulnerability exists in the Linux kernel's RapidIO mport character device interface. The issue arises during the dma_req_free() process, where a mutex is unlocked after a mapping may have already been freed, potentially leading to dereferencing an invalid object. This flaw can be exploited from userspace, which could allow attackers to affect the stability and security of affected systems. Proper precautions must be taken to ensure the mutex and mapping are handled correctly to mitigate this issue.

Affected Version(s)

Linux e8de370188d098bb49483c287b44925957c3c9b6 < 9a9929ec875ff20922c90c96fd544ae8a2a61a8d

Linux e8de370188d098bb49483c287b44925957c3c9b6

Linux e8de370188d098bb49483c287b44925957c3c9b6 < 211c68d817a3d9dc14c0026a59da7cac30f8147e

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.