{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89748","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.762Z","datePublished":"2026-09-11T19:46:53.070Z","dateUpdated":"2026-09-13T06:33:57.730Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:33:57.730Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix retry exhaustion in simple ring buffer reader swap\n\nsimple_ring_buffer_swap_reader_page() starts with retry set to 8 and\npost-decrements it only after a failed link replacement. On the final\nattempt, a successful replacement leaves retry at zero, while a failed\nreplacement leaves it at -1.\n\nThe current !retry test reverses both outcomes. It returns an error after\na successful final replacement, leaving the link update complete but the\nreader bookkeeping unfinished. After a failed final replacement, it\nfalls through and updates the head and reader pointers as though the\nreplacement succeeded, which can corrupt the ring.\n\nTreat only a negative counter as exhaustion and return the documented\n-EBUSY error."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Reached only via local tracefs reads of remotes/*/trace_pipe or remotes/*/trace, which call ring_buffer_consume/peek -> __rb_get_reader_page_from_remote() -> swap_reader_page() into simple_ring_buffer_swap_reader_page() (ARM64 nVHE hyp tracing or the TRACE_REMOTE_TEST module). No network, adjacent-radio, or physical path exists.\nAC:L - An attacker with tracefs access shrinks remotes/*/buffer_size_kb, enables tracing, and storms events via remotes/*/write_event or KVM hyp events while reading trace_pipe. That drives the writer to move the head across the eight cmpxchg retries; the attacker controls both sides and can retry until inverted exhaustion hits.\nPR:L - remotes/ files are mode 0440/0640 and use custom fops with no capable() or tracing_check_open_get_tr() check, only DAC. tracing-gid mounts on Android eng/Perfetto, ChromeOS, and developer kernels grant this to unprivileged tracing-group users, matching CVE-2026-89499 and prior CNA tracefs scores.\nUI:N - The attacker opens, configures, and reads their own remotes/*/trace_pipe and related tracefs files. No separate victim mount, click, or other user action is required.\nS:U - Corruption is of host kernel ring-buffer buffer_page lists and simple_ring_buffer metadata in the same OS security authority. A host-local tracefs user cannot use this as a VM, IOMMU, or guest-to-host escape.\nC:H - Inverted retry exhaustion leaves the reader page in the writer ring (success reported as error) or makes the host adopt a live writer page as reader (failure reported as success). Concurrent commits tear event headers so rb_event_length() returns unbounded sizes, and later peeks follow corrupted buffer_page pointers, enabling out-of-bounds kernel reads.\nI:H - After a failed final cmpxchg the function still updates head_page, reader_page, link.prev, and meta.reader.id, and the host splices buffer_page lists as if the swap succeeded. That kernel list-metadata corruption is exploitable for arbitrary writes and control-flow hijack, matching sibling remote-swap CVE-2026-89499.\nA:H - The inverted path hits WARN_ON_ONCE(prev_reader == new_reader) on the host, can infinite-spin in simple_rb_find_head() on SIMPLE_RB_LINK_HEAD_MOVING, and oopses on corrupted page pointers. panic_on_warn turns those WARNs into panics, and the attacker can retrigger the path at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/trace/simple_ring_buffer.c"],"versions":[{"version":"34e5b958bdad0f9cf16306368bbc2dc5b2a50143","lessThan":"df02489aa3aa1834659f0d20c89f7d212047d268","status":"affected","versionType":"git"},{"version":"34e5b958bdad0f9cf16306368bbc2dc5b2a50143","lessThan":"e0d3aed7b12cf37b74c7cc5265073d0263b49cde","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/trace/simple_ring_buffer.c"],"versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/df02489aa3aa1834659f0d20c89f7d212047d268"},{"url":"https://git.kernel.org/stable/c/e0d3aed7b12cf37b74c7cc5265073d0263b49cde"}],"title":"tracing: Fix retry exhaustion in simple ring buffer reader swap","x_generator":{"engine":"bippy-1.2.0"}}}}