Use-After-Free Vulnerability in Linux Kernel VFIO PCI Component
CVE-2026-89777

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-89777?

A vulnerability in the VFIO PCI component of the Linux kernel leads to potential use-after-free and double-free conditions. This issue arises from improper handling of the MSI permission table in vfio_msi_cap_len, where a dangling pointer is not cleared after memory deallocation. As a result, subsequent access to this pointer can cause data corruption or even system crashes, creating significant security risks for affected systems. The vulnerability has been addressed in updated kernel versions, encouraging all users to apply the latest patches to ensure system integrity.

Affected Version(s)

Linux 30ea32ab1951c80c6113f300fce2c70cd12659e4

Linux 30ea32ab1951c80c6113f300fce2c70cd12659e4

Linux 30ea32ab1951c80c6113f300fce2c70cd12659e4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.