CVE-2026-89609

high

Description

In the Linux kernel, the following vulnerability has been resolved: ecryptfs: hold msg ctx list lock when cleaning daemon queue ecryptfs_exorcise_daemon() drops queued messages from a dying daemon without holding ecryptfs_msg_ctx_lists_mux, but ecryptfs_msg_ctx_alloc_to_free() requires that lock. Take the list lock while moving the queued contexts back to the free list to avoid racing with other global msg ctx list users.

References

https://git.kernel.org/stable/c/7e48afafe7abc275f7b6916613bb18b821e7d94a

https://git.kernel.org/stable/c/779972513c2fa8c7938e54976f686091dafff22f

https://git.kernel.org/stable/c/4c02acbe0a2692ca9991c51e62bbe6d6b59dac31

https://git.kernel.org/stable/c/0d9636ecba34bd553ecf19049f7705505aea62fd

Details

Source: Mitre, NVD

Published: 2026-09-11

Updated: 2026-09-13

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00209