#VU124189 Use After Free in Linux kernel - CVE-2026-23259
Published: March 20, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in io_uring/rw component when handling read/write requests. A local user can trigger improper cleanup of allocated iovec structures to cause a denial of service.
Exploitation requires access to the io_uring subsystem and the ability to submit read/write requests.