{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89609","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.734Z","datePublished":"2026-09-11T19:45:11.086Z","dateUpdated":"2026-09-14T12:01:29.967Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:29.967Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\necryptfs: hold msg ctx list lock when cleaning daemon queue\n\necryptfs_exorcise_daemon() drops queued messages from a dying daemon\nwithout holding ecryptfs_msg_ctx_lists_mux, but\necryptfs_msg_ctx_alloc_to_free() requires that lock.\n\nTake the list lock while moving the queued contexts back to the free\nlist to avoid racing with other global msg ctx list users."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The missing lock is reached only via local syscalls: close() of /dev/ecryptfs runs ecryptfs_miscdev_release() into ecryptfs_exorcise_daemon(), racing PKI open/create that calls ecryptfs_wait_for_response(); no network or adjacent protocol path exists.\nAC:L - The attacker owns both sides of the race: one thread does PKI file ops so wait_for_response() list_move()s a msg_ctx under ecryptfs_msg_ctx_lists_mux, while another closes /dev/ecryptfs so exorcise_daemon() list_move()s the same or sibling nodes without that lock.\nPR:L - ecryptfs_miscdev_open() has no capability check; daemons are per-euid. An unprivileged user reaches this by running ecryptfsd on /dev/ecryptfs and using an eCryptfs mount from setuid mount.ecryptfs_private or an encrypted home, with a user-keyring PRIVATE_KEY auth token.\nUI:N - The attacker registers their own daemon, installs their own auth token, uses their own eCryptfs directory, and issues the create/open/close syscalls; no other user needs to mount, open a file, or otherwise interact.\nS:U - Corrupted global msg_ctx lists and the double-free of msg_ctx->msg stay inside the host kernel's eCryptfs messaging subsystem; this is ordinary kernel impact, not a VM, IOMMU, or sandbox escape.\nC:H - Unlocked list_move() of a queued msg_ctx racing wait_for_response() is a use-after-free of the kmalloc'd message buffer and leaves corrupted global list pointers that can be groomed to disclose kernel memory.\nI:H - The same race is a heap double-free of msg_ctx->msg plus unsynchronized list_move() writes through corrupted next/prev pointers, a classic memory-corruption primitive usable for control-flow hijacking.\nA:H - Concurrent unlocked list_move() readily oopses on LIST_POISON or a general protection fault during later list walks, and the double-free of msg_ctx->msg can panic the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ecryptfs/messaging.c"],"versions":[{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"64d8998e36cfd2bb7114f3af0aa51c5a559a39b3","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"4d50b8aea11ad9594c8704a4c647e11311ab7b19","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"956541efd125a10442f9514668bc5c852702c93b","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"ec1627bcb5b51ddd46b1ef27a9d5a9834abb0a6a","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"7e48afafe7abc275f7b6916613bb18b821e7d94a","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"0d9636ecba34bd553ecf19049f7705505aea62fd","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"4c02acbe0a2692ca9991c51e62bbe6d6b59dac31","status":"affected","versionType":"git"},{"version":"f66e883eb6186bc43a79581b67aff7d1a69d0ff1","lessThan":"779972513c2fa8c7938e54976f686091dafff22f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ecryptfs/messaging.c"],"versions":[{"version":"2.6.26","status":"affected"},{"version":"0","lessThan":"2.6.26","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.26","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/64d8998e36cfd2bb7114f3af0aa51c5a559a39b3"},{"url":"https://git.kernel.org/stable/c/4d50b8aea11ad9594c8704a4c647e11311ab7b19"},{"url":"https://git.kernel.org/stable/c/956541efd125a10442f9514668bc5c852702c93b"},{"url":"https://git.kernel.org/stable/c/ec1627bcb5b51ddd46b1ef27a9d5a9834abb0a6a"},{"url":"https://git.kernel.org/stable/c/7e48afafe7abc275f7b6916613bb18b821e7d94a"},{"url":"https://git.kernel.org/stable/c/0d9636ecba34bd553ecf19049f7705505aea62fd"},{"url":"https://git.kernel.org/stable/c/4c02acbe0a2692ca9991c51e62bbe6d6b59dac31"},{"url":"https://git.kernel.org/stable/c/779972513c2fa8c7938e54976f686091dafff22f"}],"title":"ecryptfs: hold msg ctx list lock when cleaning daemon queue","x_generator":{"engine":"bippy-1.2.0"}}}}