CVE-2026-89605

high

Description

In the Linux kernel, the following vulnerability has been resolved: ecryptfs: release message context on send failure ecryptfs_send_message_locked() moves a message context from the free list to the allocated list before sending the request to the userspace daemon. If ecryptfs_send_miscdev() fails, the context is left on the allocated list and cannot be reused. Move it back to the free list on failure and clear the caller's pointer.

References

https://git.kernel.org/stable/c/9319706316a8e79f374627554386d575a84b637f

https://git.kernel.org/stable/c/654b7e79443f5ea90849f5c1cf70c0d94bd5b10e

https://git.kernel.org/stable/c/47ce611cb13f0eefa550d5434c1afcd4217bfc3e

https://git.kernel.org/stable/c/219644a3ad5518217b2d62cad6d2c36a2308c949

Details

Source: Mitre, NVD

Published: 2026-09-11

Updated: 2026-09-13

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.002