{"id":"CVE-2026-81008","title":"kernel: interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (CVE-2026-81008)","summary":"A flaw was found in the Linux kernel's interconnect subsystem. When a dynamic memory allocation fails during path initialization, an object is prematurely freed while still being referenced in internal lists. This creates dangling pointers…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-825","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T21:01:53+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81008.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81008.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-81008"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532455"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81008"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81008"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-81008.mbox"},{"url":"https://git.kernel.org/stable/c/03c3af594dea9196cf6ca70d914b42aa8c873c35"},{"url":"https://git.kernel.org/stable/c/d4d73decdb9a44a248b1cbd04ed6f334df544d9c"},{"url":"https://git.kernel.org/stable/c/9a671125d4228357e5b929733c4593d27a273749"},{"url":"https://git.kernel.org/stable/c/fedea72e8f312fe7d0c6cb19353e61d2d5643b11"},{"url":"https://git.kernel.org/stable/c/a4e9aa7907ade87d1d96853d14e05dcf682f8363"},{"url":"https://git.kernel.org/stable/c/db8147c5d5ad2cfa21c2be566f95981b41b05de6"},{"url":"https://git.kernel.org/stable/c/d715d19cfcfe99f361adb05cefc143a95d400b87"},{"url":"https://git.kernel.org/stable/c/25c7e242aca084fdc1098248194032317dca625d"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00171,"epssPercentile":0.05678,"scores":{"vendor":7,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.454Z","slug":"CVE-2026-81008","body":"## Overview\n\nA flaw was found in the Linux kernel's interconnect subsystem. When a dynamic memory allocation fails during path initialization, an object is prematurely freed while still being referenced in internal lists. This creates dangling pointers, which can be later accessed or modified. This use-after-free vulnerability can lead to system instability or a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81008.json)\n\n**kernel: interconnect: Fix use after free in icc_get() and of_icc_get_by_index()** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204137,"id":"CVE-2026-81008","ts":1789490232020,"field":"cvss","old":"7.8","new":"7"},{"seq":183570,"id":"CVE-2026-81008","ts":1789356675928,"field":"cvss","old":"7.8","new":"4.7"},{"seq":183569,"id":"CVE-2026-81008","ts":1789356675928,"field":"severity","old":"high","new":"medium"},{"seq":153204,"id":"CVE-2026-81008","ts":1789285349537,"field":"cvss","old":null,"new":"7.8"},{"seq":153203,"id":"CVE-2026-81008","ts":1789285349537,"field":"severity","old":"none","new":"high"},{"seq":147179,"id":"CVE-2026-81008","ts":1789270199275,"field":"cvss","old":null,"new":"4.7"},{"seq":147178,"id":"CVE-2026-81008","ts":1789270199275,"field":"severity","old":"none","new":"medium"},{"seq":108928,"id":"CVE-2026-81008","ts":1789183729584,"field":"cvss","old":null,"new":"4.7"},{"seq":108927,"id":"CVE-2026-81008","ts":1789183729584,"field":"severity","old":"none","new":"medium"}]}