SB2026091233 - Improper access control in Linux kernel debugfs
Published: September 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-89745)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass debugfs lockdown protections.
The vulnerability exists due to improper access control in the debugfs lockdown check when accessing a debugfs file that uses mmap_prepare. A local user can use the file's mmap functionality to bypass debugfs lockdown protections.
The issue occurs when the kernel is operating in integrity lockdown mode.
Remediation
Install update from vendor's website.