CVE-2026-89605
Published: September 15, 2026Last modified: September 15, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: ecryptfs: release message context on send failure ecryptfs_send_message_locked() moves a message context from the free list to the allocated list before sending the request to the userspace daemon. If ecryptfs_send_miscdev() fails, the context is left on the allocated list and cannot be reused. Move it back to the free list on failure and clear the caller's pointer.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 7.8 |
| Attack Vector | LOCAL |
| Attack complexity | LOW |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity impact | HIGH |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Vulnerable (6.1.182-r0) |
| 25 LTS | linux-lts | Vulnerable (6.12.103-r0) | |
| Stream | linux-lts | Vulnerable (6.18.46-r0) |
References
- https://git.kernel.org/stable/c/177e0c32fec3602bb3b64139bb8bb610cd6722c7
- https://git.kernel.org/stable/c/219644a3ad5518217b2d62cad6d2c36a2308c949
- https://git.kernel.org/stable/c/30845ed227475a11a49ccce047837d016b7e0f49
- https://git.kernel.org/stable/c/47ce611cb13f0eefa550d5434c1afcd4217bfc3e
- https://git.kernel.org/stable/c/590fc6140e29c54d2f7839eb9df78d106ee1905e
- https://git.kernel.org/stable/c/654b7e79443f5ea90849f5c1cf70c0d94bd5b10e
- https://git.kernel.org/stable/c/743e7aeb9575c0838d8996d40d81a6b8fa5cd060
- https://git.kernel.org/stable/c/9319706316a8e79f374627554386d575a84b637f