A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.33/7.0.10. Affected is the function gpiod_find of the component Gpio Aggregator. Performing a manipulation of the argument dev_id results in use after free.

This vulnerability is identified as CVE-2026-64023. The attack is only possible with local access. There is not any exploit available.