{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89560","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.725Z","datePublished":"2026-09-11T19:44:32.085Z","dateUpdated":"2026-10-03T10:56:34.543Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:56:34.543Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlandlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation\n\nWhiteout objects are used in the upper layer of an OverlayFS to\nindicate that the file with this name does not exist in the unified\nview, even if it is present in one of the lower layer file systems.\n\nFor the userspace implementations of OverlayFS (fuse-overlayfs),\nwhiteout objects can be created from userspace as well:\n\n* mknod(2) with S_IFCHR and makedev(0, 0)\n* renameat2(2) with RENAME_WHITEOUT,\n  creating the whiteout in the old place of the moved file.\n\nThis commit guards whiteout creation in both of these cases with\nLANDLOCK_ACCESS_FS_MAKE_REG.  Whiteout objects are *not* considered\ncharacter devices and are not bound to a driver.\n\nLANDLOCK_ACCESS_FS_MAKE_REG describes the same permission class as a\nwhiteout object: creating one is the only S_IFCHR creation that the VFS\nexempts from CAP_MKNOD, so it is as unprivileged as creating a regular\nfile, while LANDLOCK_ACCESS_FS_MAKE_CHAR and\nLANDLOCK_ACCESS_FS_MAKE_BLOCK keep meaning the creation of devices that\nexpose a kernel interface [1].\n\nFor the mknod(2) case, introduce a Landlock erratum.  The creation of\nwhiteout objects through mknod(2) was previously guarded using\nLANDLOCK_ACCESS_FS_MAKE_CHAR, and it is now guarded using\nLANDLOCK_ACCESS_FS_MAKE_REG.\n\nFor the renameat2(2) case, fix a bug: Before this commit, renameat2(2)\nwith RENAME_WHITEOUT would create a directory entry even when all\nLANDLOCK_ACCESS_FS_MAKE_* rights were denied.\n\nThis does not affect normal renames within layered OverlayFS mounts:\nWhen doing a regular rename() on a mounted fuse-overlayfs, it is the\nfuse-overlayfs daemon that exercises renameat2() with RENAME_WHITEOUT,\nand only the Landlock domain of that daemon is checked there.\n\nDepends-on: 49c9e09d9610 (\"landlock: Fix handling of disconnected directories\")\nDepends-on: fe72ce6710cb (\"landlock: Add errata documentation section\")\n[mic: Record why LANDLOCK_ACCESS_FS_MAKE_REG is the matching right, and\nadd link(2) to the user doc]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bypass is reached only via local renameat2(RENAME_WHITEOUT) on a writable filesystem (tmpfs, ext4, btrfs, xfs, f2fs); Landlock's hook_path_rename runs on that syscall with no network, Bluetooth, or physical entry point.\nAC:L - The attacker triggers whiteout creation deterministically by renaming a file whose MAKE type is allowed or unhandled (the selftest uses a FIFO while MAKE_REG is denied); tmpfs supports RENAME_WHITEOUT and no race, layout, or rare config is required.\nPR:L - Only an ordinary local user in a Landlock domain is needed; vfs_mknod() exempts WHITEOUT_DEV from CAP_MKNOD, vfs_rename() never checks it, and landlock_restrict_self() is unprivileged via no_new_privs or CAP_SYS_ADMIN in a user namespace.\nUI:N - The confined process issues renameat2(RENAME_WHITEOUT) itself; no separate victim action such as mounting a filesystem or opening a crafted file is required.\nS:C - The missing MAKE_* check bypasses the Landlock sandbox, letting a confined task create OverlayFS whiteout objects in directories the policy forbade creation in, affecting filesystem resources under a separate security authority as in other Landlock policy-bypass CVEs.\nC:N - Creating a char 0:0 whiteout does not read kernel or victim memory, leak pointers, or grant Landlock READ_FILE/READ_DIR rights; WHITEOUT_DEV is not bound to a driver and opening it yields no disclosure primitive.\nI:H - A sandboxed attacker can create OverlayFS whiteout directory entries even when all LANDLOCK_ACCESS_FS_MAKE_* rights are denied, planting char 0:0 objects that hide or replace lower-layer names in an overlay upperdir and fully defeating the file-creation policy.\nA:H - OverlayFS treats planted whiteouts as deletions in the unified view, so matching lower-layer files become completely inaccessible to every consumer of that overlay, which is a total loss of availability for those protected resources."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/uapi/linux/landlock.h","security/landlock/errata/abi-1.h","security/landlock/fs.c"],"versions":[{"version":"cb2c7d1a1776057c9a1f48ed1250d85e94d4850d","lessThan":"39fc16597715125529df8f94e016fb00836ee3c1","status":"affected","versionType":"git"},{"version":"cb2c7d1a1776057c9a1f48ed1250d85e94d4850d","lessThan":"d739e32318479086efb8a6bcf5d37cf341b51f8f","status":"affected","versionType":"git"},{"version":"cb2c7d1a1776057c9a1f48ed1250d85e94d4850d","lessThan":"dfb10d989056181168ebc16781a8f39520e33200","status":"affected","versionType":"git"},{"version":"cb2c7d1a1776057c9a1f48ed1250d85e94d4850d","lessThan":"efb4f24fc2b9bcef1c41ff3392894f1fa8fba2a0","status":"affected","versionType":"git"},{"version":"cb2c7d1a1776057c9a1f48ed1250d85e94d4850d","lessThan":"627ce4902df1d737e99306daae5a87c68b876d16","status":"affected","versionType":"git"},{"version":"cb2c7d1a1776057c9a1f48ed1250d85e94d4850d","lessThan":"0c3204aacbe8c07f9e87e3028f28ec6c166a1075","status":"affected","versionType":"git"},{"version":"cb2c7d1a1776057c9a1f48ed1250d85e94d4850d","lessThan":"672fa082d48b21e1fb62cdb184fee41513e53421","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/uapi/linux/landlock.h","security/landlock/errata/abi-1.h","security/landlock/fs.c"],"versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/39fc16597715125529df8f94e016fb00836ee3c1"},{"url":"https://git.kernel.org/stable/c/d739e32318479086efb8a6bcf5d37cf341b51f8f"},{"url":"https://git.kernel.org/stable/c/dfb10d989056181168ebc16781a8f39520e33200"},{"url":"https://git.kernel.org/stable/c/efb4f24fc2b9bcef1c41ff3392894f1fa8fba2a0"},{"url":"https://git.kernel.org/stable/c/627ce4902df1d737e99306daae5a87c68b876d16"},{"url":"https://git.kernel.org/stable/c/0c3204aacbe8c07f9e87e3028f28ec6c166a1075"},{"url":"https://git.kernel.org/stable/c/672fa082d48b21e1fb62cdb184fee41513e53421"}],"title":"landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation","x_generator":{"engine":"bippy-1.2.0"}}}}