CVE-2026-89609

Summary

In the Linux kernel, the following vulnerability has been resolved:

ecryptfs: hold msg ctx list lock when cleaning daemon queue

ecryptfs_exorcise_daemon() drops queued messages from a dying daemon without holding ecryptfs_msg_ctx_lists_mux, but ecryptfs_msg_ctx_alloc_to_free() requires that lock.

Take the list lock while moving the queued contexts back to the free list to avoid racing with other global msg ctx list users.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf66e883eb6186bc43a79581b67aff7d1a69d0ff1 < 7e48afafe7abc275f7b6916613bb18b821e7d94aaffected
LinuxLinuxf66e883eb6186bc43a79581b67aff7d1a69d0ff1 < 0d9636ecba34bd553ecf19049f7705505aea62fdaffected
LinuxLinuxf66e883eb6186bc43a79581b67aff7d1a69d0ff1 < 4c02acbe0a2692ca9991c51e62bbe6d6b59dac31affected
LinuxLinuxf66e883eb6186bc43a79581b67aff7d1a69d0ff1 < 779972513c2fa8c7938e54976f686091dafff22faffected
LinuxLinux2.6.26affected
LinuxLinux0 < 2.6.26unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References