CVE-2026-89498
CVE CVE-2026-89498EUVD EUVD-2026-76404Published 2026-09-11T19:43:48.000ZLast changed 2026-09-14T12:00:33.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: orangefs: fix double-free of trailer_buf on readdir copy failure On a readdir downcall, orangefs_devreq_write_iter() frees op->downcall.trailer_buf with vfree() when copy_from_iter_full() fails, but does not clear the pointer before goto Efault. The waiter in do_readdir() is then woken with a negative status and frees the same pointer again on its r < 0 path, causing a deterministic double-free. A client holding /dev/pvfs2-req triggers it by sending a readdir downcall whose declared trailer_size exceeds the bytes it supplies. Clear the pointer after freeing so the readdir-side vfree() becomes a no-op.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 382f4581e67f57209c7aa67e39f26ba076306a2e <6e5924644ef4bce06a3cbb7cb841a8bbfdfc03ad; patch: 6.18.50; patch: 5.10.270; patch: 7.3-rc1; patch: 6.6.157; patch: 5.15.221; 382f4581e67f57209c7aa67e39f26ba076306a2e <519f4146b8b8c5f20c2ad01913acd6df2df8fc8e; 382f4581e67f57209c7aa67e39f26ba076306a2e <9c9eacc47c618ed6d7d35fe75a40d294c8cdbffa; patch: 7.2.4; patch: 0; patch: 6.1.188; 382f4581e67f57209c7aa67e39f26ba076306a2e <f574296be7f46eb60beca851240b526df232f480; 382f4581e67f57209c7aa67e39f26ba076306a2e <f796f38a324e89547738f4b70cc33be5be2bc6da; patch: 6.12.109; 382f4581e67f57209c7aa67e39f26ba076306a2e <712c4235fcc73c11a2f1d59a499d489e49c374a4; 4.12; 382f4581e67f57209c7aa67e39f26ba076306a2e <433c2e470053cc9c712314d3d8c3dfbc862d68eb; 382f4581e67f57209c7aa67e39f26ba076306a2e <2f5454a25127854c232fde5d1d65d16fbcd42d43
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.