{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89605","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.733Z","datePublished":"2026-09-11T19:45:08.101Z","dateUpdated":"2026-09-14T12:01:25.672Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:25.672Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\necryptfs: release message context on send failure\n\necryptfs_send_message_locked() moves a message context from the free\nlist to the allocated list before sending the request to the userspace\ndaemon.\n\nIf ecryptfs_send_miscdev() fails, the context is left on the\nallocated list and cannot be reused. Move it back to the free list on\nfailure and clear the caller's pointer."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only via local syscalls: open/creat on an eCryptfs mount drives pki_encrypt_session_key()/decrypt_pki_encrypted_session_key() into ecryptfs_send_message_locked(), and the per-euid daemon is registered with open(/dev/ecryptfs); no network or adjacent protocol path exists.\nAC:L - ecryptfs_send_miscdev() fails only on kmalloc(), which a local attacker in a memory cgroup can force by filling memory.max so the small GFP_KERNEL allocation returns NULL; the attacker then repeats create/open while running the daemon, with no race or other condition outside their control.\nPR:L - Neither miscdev_open() nor the PKI send path checks capabilities. An unprivileged user reaches this by running ecryptfsd on /dev/ecryptfs and using an eCryptfs mount from setuid mount.ecryptfs_private or an existing encrypted home, with a user-keyring PRIVATE_KEY auth token.\nUI:N - The attacker registers their own daemon, installs their own auth token, uses their own eCryptfs directory, and issues the create/open syscalls; no other user needs to mount, open a file, or otherwise interact.\nS:U - The leaked msg_ctx slots and any later use of the dangling msg_ctx->task pointer stay inside the host kernel's eCryptfs messaging subsystem; this is ordinary kernel impact, not a VM, IOMMU, or sandbox escape.\nC:H - A failed send leaves the msg_ctx PENDING with a raw task_struct pointer. After the sender exits, the attacker's daemon can write a MSG_RESPONSE with that index and predictable counter so ecryptfs_process_response() calls wake_up_process() on the freed task, a UAF that discloses kernel memory.\nI:H - The same task_struct use-after-free is heap-sprayable: wake_up_process() writes into a recycled task object and can hijack control flow. Stuck PENDING contexts are also never returned to the 32-slot global pool, breaking eCryptfs messaging for every user.\nA:H - Each failed send permanently removes one of 32 global msg_ctx slots from the free list until reboot, fully denying eCryptfs PKI wrap/unwrap for all users, and the dangling-task wake_up_process() path can oops or panic the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ecryptfs/messaging.c"],"versions":[{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"177e0c32fec3602bb3b64139bb8bb610cd6722c7","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"743e7aeb9575c0838d8996d40d81a6b8fa5cd060","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"590fc6140e29c54d2f7839eb9df78d106ee1905e","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"30845ed227475a11a49ccce047837d016b7e0f49","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"47ce611cb13f0eefa550d5434c1afcd4217bfc3e","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"9319706316a8e79f374627554386d575a84b637f","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"654b7e79443f5ea90849f5c1cf70c0d94bd5b10e","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"219644a3ad5518217b2d62cad6d2c36a2308c949","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ecryptfs/messaging.c"],"versions":[{"version":"2.6.26","status":"affected"},{"version":"0","lessThan":"2.6.26","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/177e0c32fec3602bb3b64139bb8bb610cd6722c7"},{"url":"https://git.kernel.org/stable/c/743e7aeb9575c0838d8996d40d81a6b8fa5cd060"},{"url":"https://git.kernel.org/stable/c/590fc6140e29c54d2f7839eb9df78d106ee1905e"},{"url":"https://git.kernel.org/stable/c/30845ed227475a11a49ccce047837d016b7e0f49"},{"url":"https://git.kernel.org/stable/c/47ce611cb13f0eefa550d5434c1afcd4217bfc3e"},{"url":"https://git.kernel.org/stable/c/9319706316a8e79f374627554386d575a84b637f"},{"url":"https://git.kernel.org/stable/c/654b7e79443f5ea90849f5c1cf70c0d94bd5b10e"},{"url":"https://git.kernel.org/stable/c/219644a3ad5518217b2d62cad6d2c36a2308c949"}],"title":"ecryptfs: release message context on send failure","x_generator":{"engine":"bippy-1.2.0"}}}}