CVE-2026-89745

Summary

In the Linux kernel, the following vulnerability has been resolved:

debugfs: Fix lockdown check for mmap_prepare

Commit 651fdda8406d ("relay: update relay to use mmap_prepare") changed the mmap file operation to mmap_prepare for relayfs, but the lockdown check in debugfs was not updated accordingly.

This prevents debugfs from being locked down when the kernel is in integrity mode if a file uses mmap_prepare but not mmap.

Since the conversion to mmap_prepare across the kernel is not yet complete, update the lockdown check to look for both mmap and mmap_prepare to ensure comprehensive coverage.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux651fdda8406d42a5004c5c79f269540a85d6a1ab < e7f6a6b5741d16fdac7adaecbe0fa52ae756f208affected
LinuxLinux651fdda8406d42a5004c5c79f269540a85d6a1ab < f81808de37338aac8e167f99bfae647b1b835c70affected
LinuxLinux6.19affected
LinuxLinux0 < 6.19unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References