Use-After-Free Vulnerability in Linux Kernel Affecting RapidIO Interface
CVE-2026-89742
Currently unrated
What is CVE-2026-89742?
A use-after-free vulnerability exists in the Linux kernel's RapidIO mport character device interface. The issue arises during the dma_req_free() process, where a mutex is unlocked after a mapping may have already been freed, potentially leading to dereferencing an invalid object. This flaw can be exploited from userspace, which could allow attackers to affect the stability and security of affected systems. Proper precautions must be taken to ensure the mutex and mapping are handled correctly to mitigate this issue.
Affected Version(s)
Linux e8de370188d098bb49483c287b44925957c3c9b6 < 9a9929ec875ff20922c90c96fd544ae8a2a61a8d
Linux e8de370188d098bb49483c287b44925957c3c9b6
Linux e8de370188d098bb49483c287b44925957c3c9b6 < 211c68d817a3d9dc14c0026a59da7cac30f8147e