{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89499","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.715Z","datePublished":"2026-09-11T19:43:48.752Z","dateUpdated":"2026-09-13T06:30:06.162Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:30:06.162Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Stop remote reader update when page swap fails\n\nThe remote swap_reader_page callback can return -EBUSY when the writer\nmoves the head before the remote catches it, particularly during an event\nstorm on a small buffer. __rb_get_reader_page_from_remote() currently\nwarns about that failure but continues with the unchanged reader ID and\nrearranges the local page list as though the swap succeeded.\n\nHandle the callback failure as a recoverable error. Report it with\npr_warn_ratelimited() and return NULL. Callers already handle a NULL reader\npage as a failed attempt. This avoids splicing the same page as both the\nprevious and new reader without flooding the log under contention."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only by a local read of tracefs remotes/*/trace_pipe or remotes/*/trace, which calls ring_buffer_peek/consume then rb_get_reader_page() and __rb_get_reader_page_from_remote(). No network, adjacent-radio, or physical-device path reaches this remote reader swap.\nAC:L - An attacker with tracefs access sets a small remotes/*/buffer_size_kb, enables tracing, generates an event storm via remotes/*/write_event or KVM hyp events, and reads trace_pipe. That is the documented -EBUSY case; the attacker controls writer load and the reader swap, so the failed-swap path is reliably hit.\nPR:L - remotes/ files are mode 0440/0640 and use custom fops with no capable() or tracing_check_open_get_tr() check, only DAC. tracing-gid mounts on Android eng/Perfetto, ChromeOS, and developer kernels grant this to unprivileged users, matching prior CNA tracefs scores.\nUI:N - The attacker opens, configures, and reads their own remotes/*/trace_pipe and related tracefs files. No separate victim mount, click, or other user action is required.\nS:U - The corruption is of host kernel ring-buffer buffer_page lists and reader metadata in the same OS security authority. A host-local tracefs user cannot use this as a VM/IOMMU/guest-to-host escape.\nC:H - On swap failure the kernel still splices the unchanged reader page into the list and shares it with the remote writer. Torn event headers make rb_event_length() return unbounded sizes, and later peeks follow corrupted buffer_page pointers, enabling out-of-bounds kernel reads.\nI:H - __rb_get_reader_page_from_remote() writes list.next/list.prev as if the swap succeeded, creating a self-referential reader and unlinking the real head. Subsequent swaps and rb_inc_page/rb_list_head_clear store further pointers on that corrupted topology, which is exploitable kernel metadata corruption.\nA:H - The failed-swap path hits WARN_ON_ONCE(prev_reader == new_reader), can infinite-loop walking the spliced list, and oopses on corrupted page pointers. panic_on_warn makes those WARNs a kernel panic, and the attacker can retrigger the path at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/trace/ring_buffer.c"],"versions":[{"version":"2e67fabd8b77c4f482df9b211bca1b495c6c2c24","lessThan":"a14a97048e48471e283d76879b83d2ae323e0722","status":"affected","versionType":"git"},{"version":"2e67fabd8b77c4f482df9b211bca1b495c6c2c24","lessThan":"5eab74874d11160725c42ab676ba97a797a362eb","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/trace/ring_buffer.c"],"versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a14a97048e48471e283d76879b83d2ae323e0722"},{"url":"https://git.kernel.org/stable/c/5eab74874d11160725c42ab676ba97a797a362eb"}],"title":"ring-buffer: Stop remote reader update when page swap fails","x_generator":{"engine":"bippy-1.2.0"}}}}