{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89552","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.723Z","datePublished":"2026-09-11T19:44:26.091Z","dateUpdated":"2026-09-11T19:44:26.091Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-11T19:44:26.091Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nparams: fix charp corruption on allocation failure\n\nparam_set_charp() stores charp parameters in allocated memory after slab is\navailable, and releases the previous value when the parameter is updated.\n\nThe previous value is released before the replacement allocation succeeds.\nIf kmalloc_parameter() fails, the setter returns -ENOMEM with the parameter\nleft as NULL.\n\nFailing zswap's compressor update before zswap is initialized can later\ntrigger:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000000\n  RIP: 0010:strcmp+0x10/0x30\n  Call Trace:\n    zswap_setup+0x3b1/0x490\n    zswap_enabled_param_set+0x5b/0xa0\n    param_attr_store+0x93/0xe0\n    module_attr_store+0x1c/0x30\n    kernfs_fop_write_iter+0x116/0x1f0\n\nAllocate and copy the replacement first, then replace the parameter value\nonly after allocation succeeds."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/params.c"],"versions":[{"version":"e180a6b7759a99a28cbcce3547c4c80822cb6c2a","lessThan":"614f873268c5b172804c9af6639bd17b7e1e2359","status":"affected","versionType":"git"},{"version":"e180a6b7759a99a28cbcce3547c4c80822cb6c2a","lessThan":"704ecd010d4a9b33160e40b74eb402f6b86a18e0","status":"affected","versionType":"git"},{"version":"e180a6b7759a99a28cbcce3547c4c80822cb6c2a","lessThan":"0d8e2404925a0607ffec79a53170715a46936896","status":"affected","versionType":"git"},{"version":"e180a6b7759a99a28cbcce3547c4c80822cb6c2a","lessThan":"3dfaae04243cde460d82dfc2a7dd0bb6664d20ae","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/params.c"],"versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/614f873268c5b172804c9af6639bd17b7e1e2359"},{"url":"https://git.kernel.org/stable/c/704ecd010d4a9b33160e40b74eb402f6b86a18e0"},{"url":"https://git.kernel.org/stable/c/0d8e2404925a0607ffec79a53170715a46936896"},{"url":"https://git.kernel.org/stable/c/3dfaae04243cde460d82dfc2a7dd0bb6664d20ae"}],"title":"params: fix charp corruption on allocation failure","x_generator":{"engine":"bippy-1.2.0"}}}}