{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89497","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.714Z","datePublished":"2026-09-11T19:43:47.439Z","dateUpdated":"2026-09-14T12:00:32.105Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:32.105Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\norangefs: skip leading spaces before parsing client debug masks\n\norangefs_prepare_cdm_array() sizes each client debug keyword buffer\nwith strcspn(cds_head, \" \"), but then parses the keyword with %s. The\n%s conversion skips leading whitespace, while strcspn() does not.\n\nIf a client debug entry starts with a space, the allocation can be sized\nfor an empty keyword while sscanf() copies the following non-empty token.\nThis can write past the end of the allocated keyword buffer.\n\nSkip leading spaces before computing the keyword length so the allocation\nmatches the string parsed by sscanf()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The overflow is reached only via ioctl(ORANGEFS_DEV_CLIENT_STRING) on /dev/pvfs2-req after orangefs_devreq_open(); orangefs_debugfs_new_client_string() copy_from_user()s the client debug-mask table from that local fd into orangefs_prepare_cdm_array(). Unlike readdir trailers, this string is not supplied by an OrangeFS server over the network.\nAC:L - A single CLIENT_STRING ioctl whose first newline-delimited entry begins with spaces then a long non-whitespace token deterministically makes strcspn() return 0 while sscanf(\"%s\") copies that token; the attacker fully controls the 2048-byte buffer and needs no race, heap layout, or other state outside their control.\nPR:L - orangefs_devreq_open() checks only init_user_ns, O_NONBLOCK, and exclusive open—no capability. The kernel documents mknod /dev/pvfs2-req, which is typically world-readable, and ioctl works on O_RDONLY, so an unprivileged local user can open the node when client-core is not holding it; user namespaces cannot open it, but init-ns DAC is enough.\nUI:N - The attacker opens /dev/pvfs2-req and issues the crafted CLIENT_STRING ioctl themselves. No victim must mount OrangeFS, start pvfs2-client-core, or otherwise interact; an already-loaded module and device node are deployment state, not user interaction.\nS:U - The heap overflow and any resulting kernel memory corruption or oops occur in the same kernel that services the ioctl. This is a standard local kernel compromise, not a VM/IOMMU/sandbox boundary crossing.\nC:H - sscanf(\"%s\") with no field width copies an attacker-chosen token (up to the 2048-byte ioctl buffer) into a kzalloc(1) keyword, a large heap overflow that can overwrite adjacent slab objects and pointers, yielding an arbitrary read primitive per CNA memory-corruption guidance.\nI:H - The same unbounded out-of-bounds write smashes heap metadata and neighboring objects with attacker-controlled bytes, which is sufficient for arbitrary write and control-flow hijack; CNA guidance rates heap buffer overflows High for integrity.\nA:H - Overflowing a 1-byte slab allocation by up to ~2KB of attacker data reliably corrupts the heap and can oops/panic the kernel even without a full exploit, so availability impact is High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/orangefs/orangefs-debugfs.c"],"versions":[{"version":"f7be4ee07fb72a516563bc2870ef41fa589a964a","lessThan":"173bfd69696815bcf1c052f61cb69c26cca4e443","status":"affected","versionType":"git"},{"version":"f7be4ee07fb72a516563bc2870ef41fa589a964a","lessThan":"995f4d05589f87452a56672270af28918c8939c3","status":"affected","versionType":"git"},{"version":"f7be4ee07fb72a516563bc2870ef41fa589a964a","lessThan":"0ef38d53bca5ea1375fea0d3d11e9727df064b85","status":"affected","versionType":"git"},{"version":"f7be4ee07fb72a516563bc2870ef41fa589a964a","lessThan":"ce748ae1181d0daf5dd0d2d906d5c1cc328c153b","status":"affected","versionType":"git"},{"version":"f7be4ee07fb72a516563bc2870ef41fa589a964a","lessThan":"15d79c806231e62a7b746d3b42626810004e1b27","status":"affected","versionType":"git"},{"version":"f7be4ee07fb72a516563bc2870ef41fa589a964a","lessThan":"116d14f29a0524853c9316f32a2ac06cff5d4bf6","status":"affected","versionType":"git"},{"version":"f7be4ee07fb72a516563bc2870ef41fa589a964a","lessThan":"1774c5b3713add32fe15ab0d3db4b73355f94e35","status":"affected","versionType":"git"},{"version":"f7be4ee07fb72a516563bc2870ef41fa589a964a","lessThan":"d410cd5303ec59c7cf23dd61423752ce8e9ecb59","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/orangefs/orangefs-debugfs.c"],"versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/173bfd69696815bcf1c052f61cb69c26cca4e443"},{"url":"https://git.kernel.org/stable/c/995f4d05589f87452a56672270af28918c8939c3"},{"url":"https://git.kernel.org/stable/c/0ef38d53bca5ea1375fea0d3d11e9727df064b85"},{"url":"https://git.kernel.org/stable/c/ce748ae1181d0daf5dd0d2d906d5c1cc328c153b"},{"url":"https://git.kernel.org/stable/c/15d79c806231e62a7b746d3b42626810004e1b27"},{"url":"https://git.kernel.org/stable/c/116d14f29a0524853c9316f32a2ac06cff5d4bf6"},{"url":"https://git.kernel.org/stable/c/1774c5b3713add32fe15ab0d3db4b73355f94e35"},{"url":"https://git.kernel.org/stable/c/d410cd5303ec59c7cf23dd61423752ce8e9ecb59"}],"title":"orangefs: skip leading spaces before parsing client debug masks","x_generator":{"engine":"bippy-1.2.0"}}}}