CVE-2026-56906: Use After Free
Published Oct 6, 2026
·Updated
In epfree of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
1 affected component
Linux Linux kernel
Event History
Oct 6, 2026
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
DescriptionWeakness
Data Sourced
via NVD·07:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
Exploitation is described as a local privilege-escalation scenario. No additional execution privileges are required.
2
Does exploitation require user interaction?
No. User interaction is not needed for exploitation.