Use-After-Free Vulnerability in Linux Kernel Affecting PowerPC Architecture
CVE-2026-93260
Currently unrated
What is CVE-2026-93260?
A use-after-free vulnerability exists in the Linux kernel's PowerPC architecture that can be triggered when the xive_init_ipis() function fails, yet the xive_smp_probe() function continues execution. This flaw occurs as the system incorrectly dereferences a pointer associated with a previously freed array, leading to potential system instability and security risks. The recent patch addresses this issue by correctly propagating errors through various related functions, ensuring that IPI setup is aborted if initializations fail, thereby enhancing the kernel's overall stability and safety.
Affected Version(s)
Linux 243e25112d06b348f087a6f7aba4bbc288285bdd
Linux 243e25112d06b348f087a6f7aba4bbc288285bdd < 411a3c016e7a95f5fa105a0587e07d0647a77727
Linux 4.12