{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89500","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.715Z","datePublished":"2026-09-11T19:43:49.392Z","dateUpdated":"2026-10-03T10:56:31.251Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:56:31.251Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Make cpu_buffer::free_page a buffer_data_read_page\n\nDiscarding a cached reader page after a concurrent ring buffer resize\nuses the new global subbuf_order for the free_pages() call. This\nmismatched order may crashes the kernel or leaks memory because the cached\npage was allocated under the old size.\n\nSave the actual free_page order alongside the page address to ensure we\nalways refer to the correct value and do not rely on the potentially\nstalled cpu_buffer->subbuf_order value. The simplest is to make\nfree_page a buffer_data_read_page which already covers exactly what we\nneed: a page address and a page order."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only via local tracefs: write() to buffer_subbuf_size_kb (buffer_subbuf_size_write -> ring_buffer_subbuf_order_set) racing read/splice/close of per_cpu/cpuN/trace_pipe_raw (ring_buffer_alloc_read_page / ring_buffer_free_read_page) or instance rmdir (rb_free_cpu_buffer). No network, adjacent-radio, or physical path exists.\nAC:L - The attacker owns both sides of the race: one thread toggles buffer_subbuf_size_kb while another caches or discards a reader page via trace_pipe_raw. The window includes synchronize_rcu() and GFP_KERNEL allocation of every new sub-buffer, so the mismatch is reliably retryable with no condition outside attacker control.\nPR:L - tracing_check_open_get_tr() enforces only LOCKDOWN_TRACEFS and DAC, with no capable() check. buffer_subbuf_size_kb is 0640 and trace_pipe_raw is 0440; Android/Perfetto, ChromeOS, and distro tracing groups routinely delegate these to unprivileged accounts, matching CVE-2024-50207, CVE-2025-38101, and CVE-2026-74634.\nUI:N - Exploitation uses the attacker's own file descriptors and threads (write buffer_subbuf_size_kb, read/close trace_pipe_raw, optional instance rmdir). No separate victim mount, click, or configuration action is required.\nS:U - Wrong-order free_pages() and reuse of a cached reader page corrupt kernel ring-buffer and buddy-allocator pages within the same OS security authority. This enables local privilege escalation but does not cross VM, IOMMU, container, or hardware trust boundaries.\nC:H - cpu_buffer->free_page stored no allocation order, so a cached page allocated under the old subbuf size can be discarded or reused with the new order. Over-free and undersized-page swap are page UAF/OOB reads; recycled buddy pages and ring-buffer contents can be disclosed through subsequent trace_pipe_raw reads.\nI:H - free_pages() with a larger-than-allocated order returns neighboring in-use pages to the buddy allocator (page UAF/write). ring_buffer_read_page() can also swap that undersized cached page into the live writer path, producing out-of-bounds kernel stores exploitable for control-flow hijack.\nA:H - Mismatched-order free_pages() corrupts the buddy allocator and the commit states this may crash the kernel; UAF/OOB on ring-buffer pages also oops/panic. The attacker chooses the order delta via buffer_subbuf_size_kb and can retrigger the race at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/trace/ring_buffer.c"],"versions":[{"version":"8e7b58c27b3c567316a51079b375b846f9223bba","lessThan":"d8f52dc3c3f1f987d8cf920ccd8d66590870bf3f","status":"affected","versionType":"git"},{"version":"8e7b58c27b3c567316a51079b375b846f9223bba","lessThan":"a1dabe68fb53730bc0be60c5dbfd3f4c560084e7","status":"affected","versionType":"git"},{"version":"8e7b58c27b3c567316a51079b375b846f9223bba","lessThan":"d787d509bdf6c88c85e095247daf7456cb7fb772","status":"affected","versionType":"git"},{"version":"8e7b58c27b3c567316a51079b375b846f9223bba","lessThan":"7a1fb95de5404134f8758c1295ce88986bdf117c","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/trace/ring_buffer.c"],"versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d8f52dc3c3f1f987d8cf920ccd8d66590870bf3f"},{"url":"https://git.kernel.org/stable/c/a1dabe68fb53730bc0be60c5dbfd3f4c560084e7"},{"url":"https://git.kernel.org/stable/c/d787d509bdf6c88c85e095247daf7456cb7fb772"},{"url":"https://git.kernel.org/stable/c/7a1fb95de5404134f8758c1295ce88986bdf117c"}],"title":"ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page","x_generator":{"engine":"bippy-1.2.0"}}}}