CVE-2026-89485
CVE CVE-2026-89485EUVD EUVD-2026-76391Published 2026-09-11T19:43:39.000ZLast changed 2026-09-14T12:00:21.000ZCVSS 9.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: lockd: pin next file across nlm_inspect_file lock-drop nlm_traverse_files() pins the current file with f_count++ across a mutex_unlock for nlm_inspect_file(), but nothing pins the saved next pointer. A concurrent nlm_release_file() can kfree the next file during the unlock window, and the iterator dereferences freed memory on the next loop step. Pin both current and next before the lock-drop. Advance by swapping the pinned cursors at the end of each iteration so next is always held alive across the unlock. Always call nlm_file_release() after dropping the iteration pin, regardless of whether the file matched the predicate. Use nlm_file_inuse(), which does a live walk of the inode lock list, rather than the cached f_locks field, so skipped files that never ran nlm_inspect_file() are evaluated correctly. Because every file in a hash bucket is now pinned and released, files skipped by the is_failover_file predicate that have no locks, blocks, shares, or external references are deleted during traversal. The old code never evaluated skipped files for cleanup. The new behavior is intentional: such files are stale and should not persist in the table.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 5.10.270; 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 <41f0a6d31615fcae261bf28a0aa50050dc93a401; patch: 0; patch: 6.12.109; 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 <08a455f87b14c7ff22ae3fdadda62a796a3a5572; patch: 7.3-rc1; patch: 7.2.4; patch: 6.1.188; 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 <c24bdb7df2f34bdc38ca8a73796f5acb40f1830c; 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 <e3c413f789eaf0170275c7eba523ead73d963f30; 2.6.18; 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 <e999a88133654c6dfc68487fb49da5f20dfa2d4f; patch: 6.18.50; 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 <550c19222c7132c888e23c9d89079ba1c9bc4cca; 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 <526c49cff3f72c3ec74752016380c7567040581b; 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 <350087f231c11efcd288c310707c40eab63ca583; patch: 6.6.157; patch: 5.15.221
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.