Double free in Linux kernel - CVE-2026-89767
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double release in ovl_create_real() in OverlayFS when handling a casefold mismatch during directory creation. A local user can mark the internal work subdirectory as casefolded after mounting an overlay filesystem and trigger a directory copy-up to cause a denial of service.
Subsequent creation operations under the affected parent directory can block indefinitely on its i_rwsem.