{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89503","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.715Z","datePublished":"2026-09-11T19:43:51.357Z","dateUpdated":"2026-10-03T10:56:32.347Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:56:32.347Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()\n\nring_buffer_alloc_read_page() is racy with ring_buffer_subbuf_order_set,\nit can allocate a reader page with an outdated order. This isn't a big\nissue, the user can still re-allocate a new reader page and try again.\n\nHowever, what is more problematic is if the value of subbuf_order\nchanges in the middle of ring_buffer_alloc_read_page(). In that case,\nbpage->order might not match the actual allocated memory.\n\nUse bpage->order for the allocation to prevent this race."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only via local tracefs: read() on per_cpu/*/trace_pipe_raw or snapshot_raw (tracing_buffers_read -> ring_buffer_alloc_read_page) racing with write() to buffer_subbuf_size_kb. No network, adjacent-radio, or physical path reaches this code.\nAC:L - The attacker controls both sides: one thread reads trace_pipe_raw while another writes buffer_subbuf_size_kb. GFP_KERNEL in alloc_cpu_data sleeps, so subbuf_order can change between the two reads in ring_buffer_alloc_read_page(); the race is reliably retried.\nPR:L - tracing_check_open_get_tr() enforces only LOCKDOWN_TRACEFS and DAC with no capable() check. trace_pipe_raw is 0440 and buffer_subbuf_size_kb is 0640, routinely delegated via gid=/mode= to tracing-group members on Android/Perfetto, ChromeOS, and developer systems.\nUI:N - Exploitation uses the attacker's own tracefs file descriptors and threads. No separate victim mount, click, or configuration action is required beyond the attacker holding tracefs access.\nS:U - Wrong-order page allocation and free corrupt the kernel buddy allocator and ring-buffer pages within the same OS security authority. This enables local privilege escalation but does not cross VM, IOMMU, or hardware trust boundaries.\nC:H - When bpage->order does not match the alloc_pages() size, later copy_to_user of a stale page_size and ring_buffer_read_page memcpy/memset over-read adjacent kernel pages, and wrong-order free_pages() corrupts the buddy allocator, yielding arbitrary kernel reads.\nI:H - free_pages() with a larger order than allocated, or memcpy/memset into an undersized sub-buffer when reader_page->order later matches the stale bpage->order, corrupts adjacent pages and the buddy allocator, which is exploitable for arbitrary kernel writes.\nA:H - Wrong-order free_pages() and out-of-bounds writes on undersized compound pages crash the kernel via buddy-allocator corruption or oops in ring_buffer_read_page/free_read_page. The attacker can retrigger the race at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/trace/ring_buffer.c"],"versions":[{"version":"bce761d757452ba5eb77e11fecc37a04b67494e7","lessThan":"2313ff69bd237aad264a5913907f374f958335a2","status":"affected","versionType":"git"},{"version":"bce761d757452ba5eb77e11fecc37a04b67494e7","lessThan":"2dc510957fe8fd098ab3c3147ebdf34d00cd2734","status":"affected","versionType":"git"},{"version":"bce761d757452ba5eb77e11fecc37a04b67494e7","lessThan":"53106e9262a310ef2c9a9321168c03705940c678","status":"affected","versionType":"git"},{"version":"bce761d757452ba5eb77e11fecc37a04b67494e7","lessThan":"e743527c5bfdceda1095bc0a9e596e2aebb6a9c3","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/trace/ring_buffer.c"],"versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/2313ff69bd237aad264a5913907f374f958335a2"},{"url":"https://git.kernel.org/stable/c/2dc510957fe8fd098ab3c3147ebdf34d00cd2734"},{"url":"https://git.kernel.org/stable/c/53106e9262a310ef2c9a9321168c03705940c678"},{"url":"https://git.kernel.org/stable/c/e743527c5bfdceda1095bc0a9e596e2aebb6a9c3"}],"title":"ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()","x_generator":{"engine":"bippy-1.2.0"}}}}