CVE-2026-89605

high

Description

In the Linux kernel, the following vulnerability has been resolved: ecryptfs: release message context on send failure ecryptfs_send_message_locked() moves a message context from the free list to the allocated list before sending the request to the userspace daemon. If ecryptfs_send_miscdev() fails, the context is left on the allocated list and cannot be reused. Move it back to the free list on failure and clear the caller's pointer.

References

https://git.kernel.org/stable/c/9319706316a8e79f374627554386d575a84b637f

https://git.kernel.org/stable/c/743e7aeb9575c0838d8996d40d81a6b8fa5cd060

https://git.kernel.org/stable/c/654b7e79443f5ea90849f5c1cf70c0d94bd5b10e

https://git.kernel.org/stable/c/590fc6140e29c54d2f7839eb9df78d106ee1905e

https://git.kernel.org/stable/c/47ce611cb13f0eefa550d5434c1afcd4217bfc3e

https://git.kernel.org/stable/c/30845ed227475a11a49ccce047837d016b7e0f49

https://git.kernel.org/stable/c/219644a3ad5518217b2d62cad6d2c36a2308c949

https://git.kernel.org/stable/c/177e0c32fec3602bb3b64139bb8bb610cd6722c7

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-76517

Details

Source: Mitre, NVD

Published: 2026-09-11

Updated: 2026-09-14

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.002