Description
In the Linux kernel, the following vulnerability has been resolved:

iio: buffer: Fix potential use-after-free in anonymous buffer release

An anonymous buffer handle holds a reference to the underlying IIO device.
The reference is dropped in the buffer handle's release function. If the
device has been removed, either through unbind or hot-unplug, the buffer
handle might hold the last reference.

The release function takes the mutex for the buffer using a guard, which
means the unlock happens after all the code in the function, including
`iio_device_put()`. If the anonymous buffer holds the last reference this
might free both the IIO device and the buffer, which contains the mutex,
leading to use-after-free when the mutex is unlocked.

Fix this by using a scoped guard just around the buffer dmabuf list access,
making sure the mutex is unlocked before releasing the IIO device.

Version 10 of the patch that introduced this issue used this exact scheme
of first unlocking and then dropping the reference [1]. During review it
was suggested to use a guard instead, and version 11 made that change [2].
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free
Action: Patch
AI Analysis

Impact

The Linux kernel’s IIO buffer subsystem had a use‑after‑free bug in the release path of anonymous buffer handles. When a device was removed or hot‑unplugged, the buffer handle could hold the last reference to the IIO device. The release function would unlock the buffer mutex after calling iio_device_put(), which could destroy the device and the mutex simultaneously, resulting in a use‑after‑free during mutex unlock. An attacker exploiting this could crash the kernel or potentially execute arbitrary code with kernel privileges.

Affected Systems

All Linux kernel releases that contain the vulnerable iio buffer release code are affected. The specific affected versions are not listed in the advisory, so any kernel version prior to the 11th patch of the iio buffer helper must be considered vulnerable. Linux kernel code is distributed by the Linux Foundation and maintained by the kernel developers.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score is less than 1%, indicating a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog, so there is no known wide‑scale active exploitation. The likely attack vector is a local privileged process that can create or manipulate IIO buffer handles after the device has been removed. The fix resolves the race between mutex unlocking and reference dropping, eliminating the use‑after‑free.

Generated by OpenCVE AI on September 18, 2026 at 07:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Linux kernel updates that include the iio buffer release fix (patch version 11 or later).
  • If a kernel update is not immediately available, ensure that no anonymous IIO buffer handles remain in use after device removal and that device removal is completed before any buffer release.
  • For systems running older kernels, consider patching the kernel source to apply the upstream change that confines the mutex unlock inside a scoped guard or use a backport if available.
  • Verify that the affected IIO devices are disabled or removed from the system if they are not required, reducing the attack surface.

Generated by OpenCVE AI on September 18, 2026 at 07:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Fix potential use-after-free in anonymous buffer release An anonymous buffer handle holds a reference to the underlying IIO device. The reference is dropped in the buffer handle's release function. If the device has been removed, either through unbind or hot-unplug, the buffer handle might hold the last reference. The release function takes the mutex for the buffer using a guard, which means the unlock happens after all the code in the function, including `iio_device_put()`. If the anonymous buffer holds the last reference this might free both the IIO device and the buffer, which contains the mutex, leading to use-after-free when the mutex is unlocked. Fix this by using a scoped guard just around the buffer dmabuf list access, making sure the mutex is unlocked before releasing the IIO device. Version 10 of the patch that introduced this issue used this exact scheme of first unlocking and then dropping the reference [1]. During review it was suggested to use a guard instead, and version 11 made that change [2].
Title iio: buffer: Fix potential use-after-free in anonymous buffer release
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:29.770Z

Reserved: 2026-09-11T19:38:34.777Z

Link: CVE-2026-89942

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:03.860

Modified: 2026-09-16T15:18:19.573

Link: CVE-2026-89942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:45:05Z

Weaknesses