CVE-2026-89502

high

Description

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Free cpu_buffer::free_page with subbuf_order When sub-buffers use an order greater than 0, cpu_buffer->free_page is allocated with subbuf_order. Use the correct order for cpu_buffer->free_page.

References

https://git.kernel.org/stable/c/8c1ecdcdea738efe0494af908f12c0ae3a97fffa

https://git.kernel.org/stable/c/81063bbb16c4fcf0136c9117d5e49d3621dd6a1e

https://git.kernel.org/stable/c/77275ccea06eaf297e8e6ac3fc830cb72086379a

https://git.kernel.org/stable/c/234b1a72e9706fe20c08c96f4374ec8e83b934cb

Details

Source: Mitre, NVD

Published: 2026-09-11

Updated: 2026-09-11

Risk Information

CVSS v2

Base Score: 6.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.002