Out-of-bounds write in Linux kernel - CVE-2026-89754
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds write.
The vulnerability exists due to improper state management in the Linux kernel mm/pagewalk page-table walker when walking page tables after a PMD entry is cleared during a retry. A local user can trigger duplicate page-walk callbacks through the mincore system call to cause an out-of-bounds write.