CVE-2026-89500
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page
Discarding a cached reader page after a concurrent ring buffer resize uses the new global subbuf_order for the free_pages() call. This mismatched order may crashes the kernel or leaks memory because the cached page was allocated under the old size.
Save the actual free_page order alongside the page address to ensure we always refer to the correct value and do not rely on the potentially stalled cpu_buffer->subbuf_order value. The simplest is to make free_page a buffer_data_read_page which already covers exactly what we need: a page address and a page order.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 8e7b58c27b3c567316a51079b375b846f9223bba < a1dabe68fb53730bc0be60c5dbfd3f4c560084e7 | affected |
| Linux | Linux | 8e7b58c27b3c567316a51079b375b846f9223bba < d787d509bdf6c88c85e095247daf7456cb7fb772 | affected |
| Linux | Linux | 8e7b58c27b3c567316a51079b375b846f9223bba < 7a1fb95de5404134f8758c1295ce88986bdf117c | affected |
| Linux | Linux | 6.8 | affected |
| Linux | Linux | 0 < 6.8 | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/a1dabe68fb53730bc0be60c5dbfd3f4c560084e7
- https://git.kernel.org/stable/c/d787d509bdf6c88c85e095247daf7456cb7fb772
- https://git.kernel.org/stable/c/7a1fb95de5404134f8758c1295ce88986bdf117c
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.