Memory corruption in Linux kernel - CVE-2026-89718
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to access slots outside of table bounds.
The vulnerability exists due to improper synchronization in writeback_store() when a device is reset and reconfigured with a smaller disksize while writeback_store() is waiting to acquire dev_lock. A local privileged user can reset and reconfigure the device with a smaller disksize during the lock acquisition to access slots outside of table bounds.