Use-After-Free Vulnerability in Linux Kernel VFIO PCI Component
CVE-2026-89777
Currently unrated
What is CVE-2026-89777?
A vulnerability in the VFIO PCI component of the Linux kernel leads to potential use-after-free and double-free conditions. This issue arises from improper handling of the MSI permission table in vfio_msi_cap_len, where a dangling pointer is not cleared after memory deallocation. As a result, subsequent access to this pointer can cause data corruption or even system crashes, creating significant security risks for affected systems. The vulnerability has been addressed in updated kernel versions, encouraging all users to apply the latest patches to ensure system integrity.
Affected Version(s)
Linux 30ea32ab1951c80c6113f300fce2c70cd12659e4
Linux 30ea32ab1951c80c6113f300fce2c70cd12659e4
Linux 30ea32ab1951c80c6113f300fce2c70cd12659e4