Improper access control in Linux kernel - CVE-2026-89745

 

Improper access control in Linux kernel - CVE-2026-89745

Published: September 12, 2026


Vulnerability identifier: #VU149056
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89745
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass debugfs lockdown protections.

The vulnerability exists due to improper access control in the debugfs lockdown check when accessing a debugfs file that uses mmap_prepare. A local user can use the file's mmap functionality to bypass debugfs lockdown protections.

The issue occurs when the kernel is operating in integrity lockdown mode.


Affected software

Linux kernel

How to mitigate CVE-2026-89745

Install security update from vendor's repository.


External References

Related Security Bulletins