{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89771","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.765Z","datePublished":"2026-09-11T19:47:10.381Z","dateUpdated":"2026-09-13T06:34:12.518Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:34:12.518Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Fix subbuf resize race with ring buffer readers\n\ntrace_buffer subbuf_size is read lockless in ring_buffer_read_page() and\nring_buffer_read_start(), while it can simultaneously be resized with\nring_buffer_subbuf_order_set().\n\nInstead of trace_buffer::subbuf_size, use bpage::order in\nring_buffer_read_start() and ring_buffer_read_page().\n\nIn ring_buffer_read_start(), even with resize_disabled, there is still a\npossibility of a race with a buffer modification. Hold the trace_buffer\nmutex to synchronise with any pending ring buffer order modification.\n\ntrace_buffer::subbuf_size is now actually useless, remove it. Also,\ncreate accessors rb_subbuf_capacity() and rb_page_capacity() which\nreturn the actual size available for storing events, while\nrb_subbuf_size() returns the actual subbuf page-size."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only via local tracefs: write() to buffer_subbuf_size_kb (ring_buffer_subbuf_order_set) racing with read()/splice() of per_cpu/*/trace_pipe_raw (ring_buffer_read_page) or open/read of trace (ring_buffer_read_start). No network, adjacent-radio, or physical path exists.\nAC:L - The attacker controls both sides: one thread writes buffer_subbuf_size_kb while another reads trace_pipe_raw or trace. ring_buffer_subbuf_order_set publishes the new subbuf_size before allocating replacement pages and without reader_lock, so the window includes synchronize_rcu() plus GFP_KERNEL allocation and is reliably retried.\nPR:L - tracing_check_open_get_tr() enforces only LOCKDOWN_TRACEFS and DAC with no capable() check. buffer_subbuf_size_kb is 0640 and trace_pipe_raw/trace are 0440/0640, routinely delegated via tracefs gid=/mode= to tracing-group members on Android/Perfetto, ChromeOS, and developer systems, matching CVE-2024-50207 and CVE-2026-74634.\nUI:N - Exploitation uses the attacker's own tracefs file descriptors and threads (write buffer_subbuf_size_kb while reading trace_pipe_raw or trace). No separate victim mount, click, or configuration action is required.\nS:U - The out-of-bounds memset/memcpy corrupt kernel ring-buffer pages and adjacent heap within the same OS security authority. This enables local privilege escalation but does not cross VM, IOMMU, container, or hardware trust boundaries.\nC:H - ring_buffer_read_page() uses the lockless new subbuf_size to memset/memcpy past an old-order spare or reader page, and tracing_buffers_read copy_to_user of that oversized length discloses adjacent kernel heap to userspace. The same OOB corruption is also a high-impact read primitive.\nI:H - After a passing order check, ring_buffer_read_page() memset()s (new_subbuf_size-size) bytes past the still-old data page (up to hundreds of KB when order jumps 0 to 7). That kernel heap OOB write is exploitable for arbitrary writes and control-flow hijack, not merely a crash.\nA:H - The same OOB memset/memcpy corrupt adjacent kernel objects and ring-buffer metadata, producing oops/panic. The attacker chooses the order delta via buffer_subbuf_size_kb and can retrigger the race at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/trace/ring_buffer.c"],"versions":[{"version":"f9b94daa542a8d2532f0930f01cd9aec2d19621b","lessThan":"6d666f0b8b36c0765cf19fbe6de5a7ba5a73aad9","status":"affected","versionType":"git"},{"version":"f9b94daa542a8d2532f0930f01cd9aec2d19621b","lessThan":"50f4a793c4ff24826efb0ac700989a5063cc53df","status":"affected","versionType":"git"},{"version":"f9b94daa542a8d2532f0930f01cd9aec2d19621b","lessThan":"0c7c517827a453128a8f58bfd849546a29813b27","status":"affected","versionType":"git"},{"version":"f9b94daa542a8d2532f0930f01cd9aec2d19621b","lessThan":"8a5f63637890f03177146efddaba5ec7a1b4d61f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/trace/ring_buffer.c"],"versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6d666f0b8b36c0765cf19fbe6de5a7ba5a73aad9"},{"url":"https://git.kernel.org/stable/c/50f4a793c4ff24826efb0ac700989a5063cc53df"},{"url":"https://git.kernel.org/stable/c/0c7c517827a453128a8f58bfd849546a29813b27"},{"url":"https://git.kernel.org/stable/c/8a5f63637890f03177146efddaba5ec7a1b4d61f"}],"title":"ring-buffer: Fix subbuf resize race with ring buffer readers","x_generator":{"engine":"bippy-1.2.0"}}}}