By weakness (CWE)
CWE-416: related vulnerabilities
CVEs classified under CWE-416. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
572 published vulnerabilities · page 4 of 6
- CVE-2026-34696HIGH 7.8
Adobe InDesign versions 21.3, 20.5.3 and earlier contain a Use After Free memory vulnerability that allows attackers to execute arbitrary code on a user's computer. The flaw requires a user to open a specially crafted malicious file—there is no remote attack vector. Once triggered, an attacker gains full control of the application and can read, modify, or delete user data, install malware, or pivot to other systems with the privileges of the logged-in user.
- CVE-2026-40290HIGH 7.8
OP-TEE is a trusted execution environment that provides a secure processing space on Arm-based processors. A race condition in OP-TEE versions 3.16.0 through 4.10.x creates a use-after-free vulnerability in the shared memory management code. The vulnerability occurs when OP-TEE is configured to manage secure partitions (a specific operational mode). A local user could exploit this by timing concurrent operations on shared memory to cause the system to access memory that has already been freed, potentially compromising the confidentiality, integrity, or availability of the secure environment.
- CVE-2026-41158HIGH 7.8
A vulnerability exists where a regular (non-privileged) user can exploit a flaw in GPU memory handling to write data to physical memory pages that have been freed by the kernel. The issue stems from improper cleanup of GPU-allocated memory—when pages are freed, the GPU can still access and modify them before they're reassigned. This allows an attacker without administrative rights to corrupt kernel memory or escalate privileges by writing to areas they shouldn't control.
- CVE-2026-42905HIGH 7.8
A use-after-free vulnerability exists in Windows DWM (Desktop Window Manager) Core Library that allows an authorized user on a Windows system to execute code and take control of the machine. The flaw requires the attacker to already have a user account on the system; it cannot be exploited remotely. When successfully exploited, an attacker can gain the highest level of system access (SYSTEM privilege), enabling complete compromise of the device. This is a local privilege escalation vulnerability affecting multiple versions of Windows 10, Windows 11, and Windows Server.
- CVE-2026-42958HIGH 7.8
CVE-2026-42958 is a use-after-free memory vulnerability in an application that processes files. When a specially crafted file is opened, the application can mishandle memory, leading to memory corruption. An attacker could exploit this to run malicious code with the same privileges as the user running the application. The vulnerability requires local access and user interaction (opening a file), but once triggered, the impact is severe.
- CVE-2026-42978HIGH 7.8
CVE-2026-42978 is a privilege escalation vulnerability in Windows Push Notifications that affects multiple versions of Windows 10, Windows 11, and Windows Server. An authenticated attacker with local access can exploit a race condition—a timing-based flaw where concurrent operations on a shared resource lack proper synchronization—to gain elevated system privileges. This is a local attack requiring an existing user account, but the consequences are severe: an attacker could gain administrative control of the affected system. The vulnerability is not currently being exploited in the wild according to public disclosures.
- CVE-2026-42979HIGH 7.8
A race condition in Windows Push Notifications allows an attacker who already has local access to a computer to gain higher-level privileges. The vulnerability exploits a timing gap in how the notification system handles shared resources, enabling privilege escalation. This is a local attack that requires an authorized user account to initiate, but could allow an attacker to break out of restricted accounts and gain administrative control.
- CVE-2026-42983HIGH 7.8
A use-after-free flaw exists in Windows Desktop Window Manager (DWM) Core Library that allows an attacker with local system access to escape their privilege level and gain full system control. The vulnerability requires the attacker to already have a foothold on the machine, but once exploited, it grants administrator-level access. This is a classic privilege escalation attack that becomes dangerous when combined with other attack chains—for instance, an attacker who gains initial access through a phishing email or vulnerable web browser can weaponize this flaw to lock down the system permanently.
- CVE-2026-42986HIGH 7.8
A use-after-free flaw in Microsoft's Graphics Component allows an authorized local user to escalate their privileges to a higher level of system access. The vulnerability requires the attacker to already have login credentials and local system access, but once exploited can lead to full control of the affected machine. This is a memory safety issue where freed memory is accessed, potentially allowing arbitrary code execution at elevated privilege levels.
- CVE-2026-42991HIGH 7.8
CVE-2026-42991 is a race condition in Windows Push Notifications that allows an authorized local user to escalate their privileges to a higher level of access. The vulnerability requires an attacker who already has login credentials and cannot be exploited remotely. It affects multiple versions of Windows 10, Windows 11, and Windows Server. While the barrier to exploitation is moderate due to timing constraints, the impact is severe—an attacker could gain system-level control.
- CVE-2026-44802HIGH 7.8
A memory safety flaw in the Windows Desktop Window Manager (DWM) Core Library allows a logged-in user to crash the system or potentially run code with elevated privileges. The vulnerability stems from use-after-free code—a situation where freed memory is accessed again—affecting multiple versions of Windows 10, Windows 11, and Windows Server. An attacker must already have a user account on the machine to exploit it, making this a local privilege escalation risk rather than a remote attack vector.
- CVE-2026-44804HIGH 7.8
A use-after-free flaw in Windows Desktop Window Manager (DWM) Core Library permits an authorized local user to escalate their privileges to a higher level of system access. The vulnerability requires legitimate account credentials and local system access but does not require user interaction. An attacker with such access could exploit this flaw to gain elevated permissions and control critical system functions.
- CVE-2026-44807HIGH 7.8
A use-after-free memory flaw exists in Windows DWM (Desktop Window Manager) Core Library that allows an authenticated local user to escalate their privileges. An attacker who already has user-level access to a system can exploit this to gain system or administrator-level control. The vulnerability requires local access and user interaction is not needed once an attacker is on the machine.
- CVE-2026-44808HIGH 7.8
A memory corruption flaw in Windows Desktop Window Manager (DWM) Core Library allows a user with local system access to escalate their privileges to a higher level of system access. The vulnerability stems from improper handling of memory buffers and requires an authenticated user to trigger, but does not require user interaction once triggered. This is a local privilege escalation vector that could allow an attacker with initial system access to gain administrative control.
- CVE-2026-44809HIGH 7.8
A use-after-free vulnerability exists in Windows' Common Log File System Driver that allows a user with local access to elevate their privileges to a higher level of system access. While the attacker must already have an account and authentication on the target system, the flaw enables them to break out of their current permission boundary and gain full control. This is a local privilege escalation (LPE) vulnerability affecting recent Windows 11 and Windows Server 2025 versions.
- CVE-2026-44811HIGH 7.8
A heap-based buffer overflow exists in Windows DWM (Desktop Window Manager) Core Library that allows a user already logged into a Windows 11 system to elevate their privileges to a higher level of access. An attacker with an existing local account would need to craft specific input or manipulate the DWM process to trigger the memory corruption, potentially gaining system-level permissions. This is a local-only vulnerability and does not enable remote compromise.
- CVE-2026-44813HIGH 7.8
A use-after-free flaw in Windows Desktop Window Manager (DWM) Core Library allows someone with local system access to escalate their privileges to a higher level of system control. An authenticated attacker—someone already logged into the machine—can exploit this memory safety issue without user interaction to gain elevated permissions, potentially taking full control of the system.
- CVE-2026-44823HIGH 7.8
Microsoft Office Excel contains a numeric truncation bug that can allow an attacker to run malicious code on a user's computer. The flaw is triggered when a user opens or works with a specially crafted Excel file, making it a local-execution risk. Since no authentication is required and user interaction (opening a file) is the only barrier, this poses a meaningful threat to organizations where Excel is widely used.
- CVE-2026-45486HIGH 7.8
A use-after-free vulnerability in Microsoft Office Word allows an attacker with local system access to execute arbitrary code by manipulating memory that has already been freed. The flaw requires user interaction—specifically opening a malicious document—but once triggered, grants the attacker full system-level privileges. This is a local execution vulnerability, not a network-based attack, meaning the attacker must either have initial access to the machine or trick a user into opening a hostile file.
- CVE-2026-45592HIGH 7.8
A flaw in Windows Internet (wininet.dll) allows a logged-in user to gain elevated system privileges through an integer overflow condition. The vulnerability requires local access and an existing user account, but does not need user interaction once exploited. This is a local privilege escalation path that impacts a wide range of Windows versions, from Windows 10 through the latest Windows 11 and several Windows Server editions.
- CVE-2026-45593HIGH 7.8
A use-after-free memory flaw in the Windows SDK enables a user with local access to gain elevated privileges on affected Windows systems. The vulnerability requires the attacker to be authenticated and logged in, but does not need user interaction to trigger. An attacker exploiting this could gain System-level access, potentially allowing them to install malware, modify system configurations, or access sensitive data.
- CVE-2026-45605HIGH 7.8
A use-after-free vulnerability in Windows Bluetooth Service enables local privilege escalation when exploited by an authenticated user. The flaw resides in memory management within the Bluetooth subsystem, allowing an attacker with valid credentials to corrupt memory and gain higher system privileges. This is not a remote attack and requires prior local access to the system.
- CVE-2026-45637HIGH 7.8
A use-after-free vulnerability exists in the Windows Desktop Window Manager (DWM) Core Library that allows an authorized local user to escalate their privileges to a higher level of system access. The vulnerability requires the attacker to already have local logon capability and is not remotely exploitable. This type of flaw occurs when software continues to reference memory that has been freed, potentially allowing an attacker to manipulate that memory and gain elevated permissions.
- CVE-2026-46111HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's Bluetooth connection handling code. When creating a Broadcast Isochronous Group (BIG) connection, the kernel can attempt to access a connection object that has already been freed. This occurs because the code doesn't properly validate that a connection still exists before operating on it, and doesn't keep a reference to the connection object while asynchronous operations are in flight. A local attacker with limited privileges could exploit this to crash the system or potentially execute code with elevated privileges.
- CVE-2026-46116HIGH 7.8
A memory safety bug exists in the Linux kernel's IPsec implementation where the xfrm_state subsystem can encounter use-after-free errors when network security policies are deleted or when network namespaces are torn down. The kernel's code was using inconsistent methods to track whether data structures were properly removed from internal lists, causing the same memory region to sometimes be deleted twice. This corrupts kernel memory and can lead to privilege escalation or denial of service on affected systems.
- CVE-2026-46120HIGH 7.8
A flaw in the Linux kernel's IPv6 GRE tunnel implementation allows a local attacker with unprivileged user namespace capabilities to trigger memory corruption. The vulnerability stems from inconsistent netns (network namespace) handling in the ip6erspan_changelink() function, which fails to use the correct cached network namespace context when reconfiguring an ERSPAN tunnel after it has been migrated between namespaces. This can lead to kernel crashes and potential privilege escalation.
- CVE-2026-46121HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's DAMON (Data Access Monitoring) subsystem, specifically in how it manages memory cgroup path strings through its sysfs interface. When users read and write the 'memcg_path' file concurrently using separate file handles, a race condition can occur where one process reads a pointer to memory that another process has already freed. This allows an attacker with local access to crash the system or potentially execute code with kernel privileges.
- CVE-2026-46180HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's Broadcom Wi-Fi driver (brcmfmac) watchdog task shutdown logic. When the kernel stops the watchdog task, a race condition can occur where the task terminates between two function calls, leaving dangling references that code attempts to access. An attacker with local access can exploit this timing weakness to crash the system or potentially execute code with elevated privileges.
- CVE-2026-46210HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's iris media driver that can be triggered when multiple instances operate concurrently. The flaw arises from a timing gap: while one thread checks video format parameters (width and height) during a macro block validation, another thread may simultaneously free those same format structures. This leaves the checker reading memory that has already been released, potentially crashing the kernel or allowing privilege escalation. The vulnerability requires local access and is triggered through normal kernel operations when multiple media encoding or decoding sessions run in parallel.
- CVE-2026-46213HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's Apple keyboard HID driver (appletb-kbd). When the driver unloads or encounters an error during initialization, a cleanup race condition allows a timer callback to access freed memory. The timer can fire after the backlight device is deallocated but before the driver has fully stopped listening for hardware events, causing kernel memory corruption. An attacker with local access and the ability to trigger driver unload or timing conditions could crash the system or potentially execute code with kernel privileges.
- CVE-2026-46215HIGH 7.8
A race condition exists in the Linux kernel's DRM (Direct Rendering Manager) subsystem, specifically in the change_handle function. When an application changes a graphics handle, the kernel briefly maintains two references to the same object in its internal tracking structures. A concurrent operation can delete the graphics object while one reference remains valid, leaving a dangling pointer that could later be dereferenced, causing a crash or potential code execution. The fix involves properly nullifying the old handle before performing operations, matching a defensive pattern already used elsewhere in the DRM code.
- CVE-2026-46219HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's MPC52xx SPI driver. When the driver is unbound (e.g., during module unload or device removal), a scheduled work queue task can attempt to access driver state that has already been freed, potentially leading to memory corruption or a kernel crash. The vulnerability arises from a race condition: the interrupt handler schedules work, but the unbind routine disables interrupts without ensuring the scheduled work completes before freeing resources.
- CVE-2026-46227HIGH 7.8
A race condition exists in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation that can lead to use-after-free or type-confusion memory safety violations. The vulnerability occurs when the kernel broadcasts messages to multiple SCTP associations while temporarily releasing the socket lock. During this window, another thread can migrate or free an association that the broadcast operation cached as the next item to process. This can result in the kernel operating on freed memory or misinterpreting data structures, potentially allowing local attackers to gain control over kernel execution flow.
- CVE-2026-46240HIGH 7.8
A use-after-free vulnerability was introduced in the Linux kernel's Iris media driver through a recent change meant to improve buffer lifecycle management. The bug occurs in the iris_release_internal_buffers() function, where a buffer object continues to be accessed after it has been freed by a called function. This type of memory safety issue can allow a local attacker with user-level privileges to corrupt kernel memory or execute arbitrary code with kernel privileges.
- CVE-2026-46241HIGH 7.8
CVE-2026-46241 is a use-after-free vulnerability in the Linux kernel's MPC52xx SPI controller driver. When the controller registration process fails, the driver fails to properly clean up allocated interrupt resources. This leaves freed memory accessible, creating a window for potential exploitation and causing a resource leak. The issue affects systems using the MPC52xx SPI controller on Linux and was discovered during a review of related deregistration code.
- CVE-2026-46242HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's event polling (epoll) subsystem. When the kernel removes an epoll watch, it clears a file structure pointer while still actively using that same structure. If another process simultaneously closes the file, a race condition can occur where freed memory gets overwritten with stale data, or worse, memory from one cache gets incorrectly freed to another. This is particularly dangerous when epoll is watching another epoll object (a technique called nested epoll), and requires local access to trigger. An unprivileged user can exploit this to crash the system or potentially escalate privileges.
- CVE-2026-46246HIGH 7.8
A race condition in the Linux kernel's power supply driver (pm8916_lbc) can cause the system to crash or corrupt memory during device removal. The bug stems from a resource initialization order problem: an interrupt handler is registered before its associated data structure (extcon handle) is fully set up. When the device is removed, the data structure gets freed before the interrupt handler is disabled, creating a window where a pending interrupt could try to use already-freed memory. This is a use-after-free vulnerability that requires local access to trigger.
- CVE-2026-46267HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's NFC (Near Field Communication) SHDLC (Synchronous Half-Duplex Link Control) driver. The vulnerability occurs during driver shutdown when memory is freed while background timers and worker threads are still active. These timers and workers can attempt to access the freed memory after it has been released, potentially leading to system crashes or privilege escalation. A local attacker with basic user privileges can trigger this condition.
- CVE-2026-46274HIGH 7.8
A memory safety bug exists in the Linux kernel's I/O work queue subsystem that can allow a local attacker with user privileges to corrupt kernel memory and crash the system or gain elevated privileges. The vulnerability arises from incomplete validation when removing pending work items from the queue, causing the kernel to retain a dangling pointer to freed memory. When that corrupted pointer is subsequently accessed, it can trigger a write to already-freed kernel structures, leading to heap corruption and potential privilege escalation.
- CVE-2026-46280HIGH 7.8
A vulnerability exists in the Linux kernel's HMM (Heterogeneous Memory Management) testing module where device memory pages are not properly returned to system memory when a test file is closed. This creates a situation where the kernel retains references to freed memory structures. If the system later tries to access those orphaned pages—such as during a crash dump—it will attempt to dereference invalid memory pointers, causing a kernel panic. The issue was observed on ARM64 systems during automated testing.
- CVE-2026-46285HIGH 7.8
A use-after-free memory safety bug exists in the Linux kernel's docg3 driver (NAND flash memory controller). When the driver is unloaded or a device is released, a pointer to the main docg3 structure is dereferenced after the memory it points to has already been freed. This can lead to a crash or, in certain conditions, potential code execution. The fix is straightforward: use an already-available pointer to the cascade structure instead of trying to access the freed docg3 object.
- CVE-2026-46301HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's Topcliff PCH SPI driver that occurs when the driver is unbound from a device. The driver attempts to access DMA buffers after they have already been released from memory, potentially causing a crash or allowing local code execution. The flaw stems from improper sequencing during driver unbind—the queue is not flushed before the DMA resources are deallocated, leaving dangling pointers.
- CVE-2026-46308HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's power domain management code for MediaTek processors. The vulnerable function releases a device node reference too early, before checking if a subsequent operation failed. If that operation fails, error-handling code attempts to read the already-freed memory to generate a diagnostic message, potentially causing a crash or memory corruption. An attacker with local system access could exploit this to elevate privileges or cause a denial of service.
- CVE-2026-46319HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's traffic control act_ct module. When a traffic control policy is initialized, the code looks up a flow table object and then attempts to increment its reference counter—but between the lookup and the increment, the object can be freed by a separate cleanup process. An attacker with local access could exploit this race condition to cause a kernel crash or execute code with elevated privileges. The vulnerability requires precise timing to trigger but is feasible in environments where multiple processes interact with traffic control policies simultaneously.
- CVE-2026-46323HIGH 7.8
A vulnerability in the Linux kernel's Generic Receive Offload (GRO) handler can cause a use-after-free condition when processing zerocopy network packets. The kernel's packet reassembly logic failed to account for zerocopy buffers that don't hold traditional page references, allowing freed memory to be accessed when fragments are incorrectly merged. This affects local processes with network capabilities on vulnerable systems.
- CVE-2026-46330HIGH 7.8
A vulnerability in the Linux kernel's SMC (Shared Memory Communications) protocol implementation allows a local, authenticated attacker to crash the system or potentially execute code with elevated privileges. The flaw stems from a TCP ULP (Upper Layer Protocol) feature that incorrectly modifies core kernel file system structures in ways that violate fundamental assumptions about how those structures should behave, leading to memory safety violations. The kernel maintainers have resolved this by removing the problematic feature entirely, as the design approach was fundamentally flawed and alternatives exist for achieving the same transparency goals.
- CVE-2026-47331HIGH 7.8
Ubuntu Linux kernel version 6.8 contains a critical flaw in the AppArmor security module where protective locks are not properly acquired during linked list modifications. This oversight allows an unprivileged local user to create a race condition that results in a use-after-free memory error. While arbitrary code execution is theoretical at this stage, the vulnerability poses a serious risk to system integrity and confidentiality. An attacker with local system access could potentially escalate privileges or compromise sensitive data.
- CVE-2026-47912HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory vulnerability that allows an attacker to execute arbitrary code on a victim's computer with the privileges of the logged-in user. The attack requires the victim to open a specially crafted malicious PDF file. Versions 24.001.30365, 26.001.21651, and earlier on Windows and macOS are affected. This is a serious flaw because it bypasses the application's normal security controls and gives attackers direct code execution capability.
- CVE-2026-47913HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory flaw that allows an attacker to execute arbitrary code if a user opens a specially crafted PDF file. The vulnerability affects Acrobat Reader version 24.001.30365, 26.001.21651 and earlier on both Windows and macOS. Because exploitation requires the victim to manually open a malicious document, this is not a wormable vulnerability, but it represents a meaningful risk in environments where users regularly receive files from untrusted sources.
- CVE-2026-47914HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory safety bug that allows attackers to execute arbitrary code on a victim's system. The vulnerability is triggered when a user opens a specially crafted PDF file, making it a file-based attack that relies entirely on social engineering or misdirection to succeed. Versions 24.001.30365, 26.001.21651, and earlier are vulnerable. Once exploited, an attacker gains the same privileges as the logged-in user, potentially enabling data theft, malware installation, or lateral movement within a network.
- CVE-2026-47915HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory vulnerability that allows attackers to execute arbitrary code with the privileges of the user running the application. The flaw affects Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier on Windows and macOS. An attacker must trick a user into opening a specially crafted malicious document for the vulnerability to be exploited. Once triggered, the attacker gains full control over the affected system, potentially allowing data theft, system compromise, or lateral movement within your network.
- CVE-2026-47916HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory defect that attackers can exploit to run arbitrary code with the same privileges as the user opening the file. The vulnerability affects multiple Acrobat Reader versions and requires an attacker to trick a user into opening a specially crafted malicious PDF or document. While the technical barrier to triggering the flaw is low, successful exploitation still depends on user action—someone must be convinced to open the dangerous file.
- CVE-2026-47917HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory defect that allows attackers to execute code with the same privileges as the user running the application. The vulnerability exists in versions 24.001.30365, 26.001.21651 and earlier on Windows and macOS systems. An attacker must trick a user into opening a specially crafted file to trigger the flaw, making this a file-based attack vector rather than a remote network vulnerability.
- CVE-2026-47918HIGH 7.8
Adobe Acrobat Reader contains a use-after-free vulnerability that allows attackers to execute arbitrary code on affected systems. The flaw requires a victim to open a malicious PDF or similar file, at which point the attacker's code runs with the same permissions as the user. Versions 24.001.30365, 26.001.21651, and earlier on Windows and macOS are vulnerable. This is a high-severity issue that should be prioritized for patching.
- CVE-2026-47919HIGH 7.8
Adobe Acrobat Reader contains a use-after-free flaw that allows an attacker to execute arbitrary code on a victim's computer. The attack requires the victim to open a specially crafted malicious PDF or document file. Once executed, the attacker gains the same privileges as the user running Acrobat Reader, potentially enabling data theft, system compromise, or further lateral movement.
- CVE-2026-47920HIGH 7.8
Adobe Acrobat Reader contains a use-after-free memory vulnerability that allows an attacker to execute arbitrary code with the privileges of the user opening a malicious PDF file. The vulnerability affects Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier on both Windows and macOS. Successful exploitation requires social engineering to convince a user to open a specially crafted document, but once opened, the attacker gains full code execution in that user's security context.
- CVE-2026-47921HIGH 7.8
Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier contain a use-after-free memory vulnerability that allows attackers to execute arbitrary code with the privileges of the logged-in user. The attack requires social engineering—a victim must be tricked into opening a malicious PDF or related file. This is a practical threat because Acrobat Reader is ubiquitous in enterprise and consumer environments, and users routinely open files from untrusted sources.
- CVE-2026-47955HIGH 7.8
A Use After Free flaw in Adobe Acrobat Reader allows an attacker to execute arbitrary code on a victim's computer. The vulnerability exists in specific versions of Reader (24.001.30365, 26.001.21651 and earlier) and requires the victim to open a specially crafted malicious file. Once exploited, the attacker gains the same privileges as the user running the application, potentially allowing them to steal data, install malware, or modify documents.
- CVE-2026-48583HIGH 7.8
A use-after-free vulnerability exists in the Windows Kernel that allows an attacker with local access and standard user privileges to escalate their access to system-level permissions. The flaw stems from improper memory management in kernel code, where memory is freed but then accessed again, potentially enabling arbitrary code execution at the highest privilege level.
- CVE-2026-49412HIGH 7.8
A critical flaw in the FreeBSD kernel's IPv6 multicast filter handling creates a use-after-free vulnerability. When a user configures IPv6 multicast filters, the kernel briefly releases a lock to safely copy filter settings from user memory. During this window, another thread can delete the filter structure entirely. When the kernel reacquires the lock and resumes work, it holds a pointer to memory that has already been freed—a classic use-after-free condition. An unprivileged local user can deliberately trigger this race condition to execute arbitrary code with kernel privileges.
- CVE-2026-50257HIGH 7.8
A use-after-free vulnerability exists in the X.Org X server and Xwayland that allows an attacker to crash the display server or potentially escalate privileges. The flaw occurs in the miSyncDestroyFence() function when multiple X clients interact with fence synchronization primitives. An attacker would establish a fence trigger, then have a second connection destroy it prematurely, leaving the first client's code trying to reference memory that has been freed. If the X server runs with root privileges—common in many deployments—this could lead to privilege escalation.
- CVE-2026-50260HIGH 7.8
A use-after-free vulnerability exists in the X.Org X server and Xwayland display servers. An attacker with local access can exploit this by creating multiple synchronized counters through one client connection, then destroying them from a separate connection, causing the server to access memory that has already been freed. This can crash the display server or, if the X server runs with root privileges, potentially allow privilege escalation to system administrator level.
- CVE-2026-50261HIGH 7.8
A use-after-free memory vulnerability exists in the X.Org X server and Xwayland, specifically in the SyncChangeCounter() function. An attacker with local access can exploit this by setting up multiple sync counters from one client connection and then destroying them from a second connection while modifying the counters. This creates a window where the server attempts to access memory that has already been freed, potentially crashing the display server or—in cases where the X server runs with root privileges—enabling privilege escalation.
- CVE-2026-52912HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's netfilter bridge packet queuing mechanism. When bridge packets are queued for userspace processing via NFQUEUE, the kernel can lose track of the correct network device reference. If the bridge is torn down while packets remain queued, reinjecting those packets causes the kernel to access memory that has already been freed, potentially leading to system crash or code execution with local privilege.
- CVE-2026-52943HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's network packet handling code. When the kernel copies packet metadata during certain fragmentation operations, it fails to properly track reference counts for zero-copy transmission buffers. This causes the kernel to prematurely free buffer structures that are still in use by active network packets, leading to memory corruption. An unprivileged local user can exploit this to gain full root-level control of the system.
- CVE-2026-52947HIGH 7.8
A critical race condition exists in the Linux kernel's QRTR (Qualcomm Technologies IPC Router) networking module. When a port is being removed, the code decrements a socket's reference counter prematurely—before the port data structure is fully cleaned up and before other parts of the kernel finish their work. This creates a narrow but exploitable window where another part of the kernel can try to use the socket while its reference count has already dropped to zero, leading to memory corruption and potential arbitrary code execution. The vulnerability was discovered during automated fuzzing and has been confirmed to cause refcount saturation warnings and use-after-free conditions.
- CVE-2026-52950HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's DRM/XE DMA-buf subsystem. The flaw occurs when the kernel attempts to retry an operation after an error condition, but the underlying memory object has already been freed, causing the kernel to reference invalid memory. An attacker with local access and unprivileged user privileges could exploit this to crash the system or potentially execute arbitrary code with kernel-level permissions.
- CVE-2026-52951HIGH 7.8
A race condition exists in the Linux kernel's Direct Rendering Manager (DRM) Xe driver when handling DMA buffer imports from other GPUs. The vulnerability occurs because the driver attaches a buffer object to a DMA buffer before fully initializing it, creating a window where external drivers (like AMD's amdgpu) can trigger callbacks that access an incomplete or freed buffer object. This can result in null pointer dereferences and use-after-free conditions, potentially crashing the system. The issue primarily affects systems importing GPU memory from AMD GPUs.
- CVE-2026-52971HIGH 7.8
A race condition vulnerability exists in the Linux kernel's Elastic Network Adapter (ENA) driver's precision hardware clock (PHC) implementation. The issue occurs when the driver checks whether the PHC is active and caches a memory pointer without holding a required lock. If the PHC is destroyed at precisely the wrong moment, the pointer becomes invalid, but the code continues to use it, resulting in a use-after-free condition. An unprivileged local user with the ability to load/unload kernel modules or trigger PHC operations could potentially crash the system or execute code with kernel privileges.
- CVE-2026-52973HIGH 7.8
A vulnerability in the Linux kernel's futex (fast userspace mutex) subsystem can allow a local attacker with user privileges to corrupt memory and crash the system. The issue arises from overly restrictive checks in how the kernel allocates shared futex hash tables when processes clone and share memory. By exploiting how the kernel tracks futex references, an attacker can trigger use-after-free conditions that lead to kernel panics or potential privilege escalation. The fix loosens the clone detection logic to properly handle all memory-sharing scenarios, not just traditional pthreads.
- CVE-2026-52976HIGH 7.8
CVE-2026-52976 is a use-after-free vulnerability in the Linux kernel's display and graphics subsystem (DRM/XE driver). The flaw exists in error handling code within the execution queue creation function. When certain resource allocation failures occur during queue setup, the kernel's cleanup logic fails to properly remove the queue from internal tracking structures before freeing memory. This leaves dangling pointers that can be dereferenced later, potentially allowing a local attacker with standard user privileges to corrupt kernel memory, escalate privileges, or crash the system.
- CVE-2026-53005HIGH 7.8
A memory safety flaw in the Linux kernel's AF_UNIX socket implementation can allow a local attacker with limited privileges to crash the system or potentially gain elevated access. The vulnerability arises from how the kernel handles socket redirects through SOCKMAP when file descriptors (critical system resource handles) are being transferred between sockets. The kernel's garbage collection mechanism fails to properly track these redirected sockets, leading to a use-after-free condition—accessing memory that has already been freed. This is particularly dangerous because it undermines the kernel's ability to safely manage file descriptor lifecycle.
- CVE-2026-53009HIGH 7.8
A memory management bug exists in the Linux kernel's Intel ice network driver. When packet transmission setup fails, the driver frees a network buffer (skb) but leaves a reference to it marked as still valid. If the network interface is then shut down without sending another packet, the driver attempts to free the same buffer twice, causing a crash or memory corruption. This is a local privilege escalation vulnerability affecting systems running vulnerable Linux kernels with the ice driver.
- CVE-2026-53011HIGH 7.8
A memory safety bug exists in the Linux kernel's traffic scheduling subsystem (taprio). When the scheduler switches from an administrative schedule to an operational one, the code frees the old schedule but continues to access it, leading to a use-after-free condition. An attacker with local access and basic privileges can trigger this flaw, potentially crashing the kernel or executing arbitrary code. The fix involves selecting the next scheduling entry from the new schedule immediately after the switch, rather than continuing to use stale pointers from the freed memory.
- CVE-2026-53024HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's Greybus raw character device driver. If a user writes data to the device after it has been disconnected, the kernel attempts to use memory that has already been freed, causing a kernel panic. The issue stems from improper synchronization between the write operation and the disconnect handler—disconnect destroys the connection object while a concurrent write may still be trying to access it.
- CVE-2026-53025HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's Greybus raw driver. When a raw bundle device is disconnected while an application still has its character device open, closing that file descriptor later triggers a memory access violation. The kernel attempts to release memory that has already been freed, causing a crash or panic. This is a local privilege escalation issue that requires an authenticated user to trigger.
- CVE-2026-53033HIGH 7.8
A race condition exists in the Linux kernel's BPF sockmap implementation for Unix domain sockets. When a BPF iterator program updates a sockmap while a socket connection is closing, a stale pointer can be dereferenced, leading to a use-after-free memory error. An attacker with local access and unprivileged user privileges can exploit this by crafting a BPF program that interacts with sockmap operations concurrent with socket state transitions, potentially causing a kernel crash or memory corruption.
- CVE-2026-53085HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's BPF task_vma iterator. When BPF programs iterate through a task's virtual memory regions, the code reads the task's memory descriptor (mm_struct) without properly securing a reference to it. If the task exits while the iteration is happening, the memory descriptor can be freed, causing the BPF code to access freed memory. This affects systems running vulnerable kernel versions where unprivileged users or privileged BPF programs can trigger the flaw through specially crafted BPF programs that use open-coded task_vma iteration.
- CVE-2026-53089HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's BPF (Berkeley Packet Filter) subsystem when querying information about offloaded maps or programs. The vulnerability occurs during network namespace destruction: when code attempts to safely reference a network namespace associated with an offloaded BPF resource, it may inadvertently try to increment a reference counter that has already reached zero. This can lead to memory corruption or denial of service. The fix involves checking whether the namespace is still alive before attempting to reference it, and gracefully returning an error if the namespace is being torn down.
- CVE-2026-53097HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's MT7996 Wi-Fi driver code. When the wireless adapter is being removed from the system, a background worker thread may still be trying to access data structures that have already been freed, causing a crash or potential code execution. The issue stems from improper synchronization between the device removal process and a pending diagnostic dump operation.
- CVE-2026-53098HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's MediaTek WiFi driver (mt76) for the MT7915 chipset. When a device is removed, the driver can attempt to access memory that has already been freed, causing a crash or potential security issue. This happens because cleanup code doesn't properly wait for background work tasks to finish before releasing the data those tasks might still be using. The vulnerability requires local access to trigger and affects systems with MT7915 WiFi hardware running vulnerable kernel versions.
- CVE-2026-53109HIGH 7.8
CVE-2026-53109 is a memory management bug in the Linux kernel's PowerPC architecture code that can cause a system crash or data corruption when page table fragments are freed. The vulnerability occurs in a specific scenario involving deferred page table cleanup (introduced in a recent kernel patch series) combined with process exit. When certain conditions align—particularly when cached page table fragments retain references but are freed during program termination—the kernel incorrectly manages the active flag on memory pages, leading to a kernel panic with "Bad page state" errors. This is a local vulnerability requiring user-level code execution on an affected system.
- CVE-2026-53112HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's rtlwifi WiFi driver for PCI devices. When a WiFi card is removed or initialization fails, a background task (irq_prepare_bcn_tasklet) may continue running and attempt to access memory that has already been freed, potentially causing a crash or allowing a local attacker with user privileges to corrupt kernel memory or escalate privileges.
- CVE-2026-53115HIGH 7.8
A vulnerability in the Linux kernel's fsl-mc (Freescale Management Complex) bus driver allows local attackers to trigger a use-after-free condition when the kernel probes drivers. The issue stems from improper synchronization: the driver override field is accessed without holding the necessary device lock during the driver attachment process, creating a race condition that could lead to privilege escalation or system compromise on affected systems.
- CVE-2026-53116HIGH 7.8
A race condition in the Linux kernel's AP (Adjunct Processor) bus driver can lead to a use-after-free memory vulnerability when AP security masks are updated concurrently with driver override settings. An attacker with local access could exploit this to crash the kernel or potentially execute code, though practical exploitation requires specific timing and local system access. The issue stems from insufficient locking around shared data structures, allowing one operation to free memory while another is still reading it.
- CVE-2026-53117HIGH 7.8
A use-after-free (UAF) vulnerability exists in the Linux kernel's s390 channel I/O subsystem. The vulnerability occurs when the kernel probes a driver and accesses the driver_override field without holding the necessary device lock, creating a race condition where the field could be accessed after being freed. This allows a local attacker with standard user privileges to corrupt memory, potentially leading to privilege escalation or system crash.
- CVE-2026-53118HIGH 7.8
A race condition exists in the Linux kernel's vdpa (vhost data path acceleration) subsystem where the driver override mechanism can be accessed without proper locking. When the kernel attempts to attach a driver to a device, it calls the bus match function without holding the device lock. If another process simultaneously modifies the driver_override field, this can lead to a use-after-free (UAF) condition, where freed memory is incorrectly accessed. The fix involves adopting the kernel's generic driver_override infrastructure, which handles locking internally to prevent concurrent access issues.
- CVE-2026-53119HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's WMI (Windows Management Instrumentation) platform driver. The issue occurs when the kernel probes a driver and accesses the driver_override field without proper locking, allowing a local attacker with standard user privileges to cause memory corruption. An attacker could exploit this to read sensitive memory, modify kernel data structures, or crash the system.
- CVE-2026-53120HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's PCI driver handling code. When the kernel attempts to attach a driver to a PCI device, it accesses configuration data (driver_override) without proper synchronization. An attacker with local access could potentially exploit this race condition to read sensitive kernel memory, modify kernel data, or execute code with kernel privileges. The vulnerability affects Linux kernel versions that use the affected PCI probe path.
- CVE-2026-53129HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's memory cache management system. When a filesystem (ext2, ext4, or ocfs2) is unmounted, the cache cleanup code frees memory before ensuring that a background shrink worker thread has stopped running. If the worker thread is still active, it will attempt to access the freed memory, causing a crash or potential code execution. This affects only privileged users who can unmount filesystems, limiting the immediate risk surface.
- CVE-2026-53156HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's NVMEM (non-volatile memory) subsystem. The issue occurs in error handling code paths where the kernel prematurely frees memory associated with an NVMEM device, then continues to access that same freed memory. This can lead to unpredictable behavior, including information disclosure, data corruption, or system crashes. The vulnerability requires local access and valid user privileges to trigger.
- CVE-2026-53157HIGH 7.8
A memory safety flaw exists in the Linux kernel's Phonet networking subsystem. When a Phonet device is destroyed, the kernel removes it from a shared list but immediately frees the memory. Other parts of the kernel can still be accessing that same memory after it's freed, causing a crash or potential code execution. The fix ensures the kernel waits for all readers to finish before reclaiming the memory.
- CVE-2026-53160HIGH 7.8
A race condition in the Linux kernel's fastrpc driver allows a local attacker to trigger a use-after-free vulnerability. The vulnerability occurs when one code path looks up a map object, releases its lock, and then tries to acquire a reference to that object—but a concurrent operation can delete the object in the interim, leaving the first operation with a dangling pointer. An attacker with local system access can exploit this timing gap to cause a kernel crash or potentially execute code with kernel privileges.
- CVE-2026-53161HIGH 7.8
CVE-2026-53161 is a use-after-free vulnerability in the Linux kernel's fastrpc (fast RPC) driver, a Qualcomm component that handles communication with digital signal processors (DSPs). The flaw occurs when a user closes their connection to the driver while the system is still processing responses from the DSP. The driver can attempt to access data structures that have already been freed, potentially leading to kernel crashes or privilege escalation. This vulnerability requires local access and user-level privileges to trigger, making it primarily a concern for multi-user systems or those where untrusted local users have accounts.
- CVE-2026-53185HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's zram compression layer. When zram writes data using a backing device (writeback mode), a race condition causes the kernel to free a memory page while an asynchronous read operation is still writing to it. This can lead to memory corruption, denial of service, or local privilege escalation by unprivileged users.
- CVE-2026-53192HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's ALSA (Advanced Linux Sound Architecture) timer subsystem. When a userspace timer is closed and freed, other running tasks may still hold references to timer instances associated with that timer object. Under concurrent access conditions, the SNDRV_TIMER_IOCTL_PARAMS ioctl call lacks proper synchronization, allowing it to access freed memory. An attacker with local user privileges can trigger this race condition to crash the system or potentially execute code with elevated privileges. The fix adds mutex protection to the vulnerable ioctl handler.
- CVE-2026-53193HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's ALSA timer subsystem. When a timer object is destroyed while slave timer instances are still active and linked to a master instance, those slave instances may retain pointers to freed memory. This can occur in typical scenarios where one application creates and destroys a timer (particularly userspace-driven timers via CONFIG_SND_UTIMER) while other applications continue to access it. The kernel fix ensures that all timer instances are properly closed and detached before cleanup, preventing orphaned references to freed memory.
- CVE-2026-53212HIGH 7.8
A use-after-free vulnerability exists in the Linux kernel's netfilter tunnel implementation. When the tunnel object is destroyed, the code improperly frees memory without accounting for packets that may still hold references to that memory. If packets queued in network discipline systems (like netem) eventually attempt to release their references, they operate on already-freed memory, causing a kernel crash or potential code execution. The fix replaces an unsafe free operation with proper reference-counting semantics.
- CVE-2026-53234HIGH 7.8
A use-after-free vulnerability exists in the IBM EMAC network driver in the Linux kernel. During device removal, the driver defers network device unregistration until after hardware teardown, creating a window where the network stack can still process packets and access freed memory. This can lead to crashes or potential privilege escalation on systems running affected kernel versions. The fix involves explicitly unregistering the network device before tearing down hardware, eliminating the unsafe race condition.
- CVE-2026-53239HIGH 7.8
CVE-2026-53239 is a use-after-free memory corruption vulnerability in the Linux kernel's IPsec policy management subsystem. The flaw occurs in the xfrm (transform) layer when handling policy deletion and rebuild operations concurrently. A local attacker with user-level privileges can trigger a race condition that causes the kernel to access memory that has already been freed, potentially leading to privilege escalation or system crash. This is a kernel-level defect that requires code execution on the target system but no special capabilities to trigger.