Sensitive Information in Resource Not Removed Before Reuse in Linux kernel - CVE-2026-89642

 

Sensitive Information in Resource Not Removed Before Reuse in Linux kernel - CVE-2026-89642

Published: September 12, 2026


Vulnerability identifier: #VU149171
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89642
CWE-ID: CWE-226
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to incomplete clearing of page-cache data in cifs_setsize() when extending a file. A local user can extend a file to disclose sensitive information.

Dirty bytes in the page region spanning the previous end of file can be written back to the server.


Affected software

Linux kernel

How to mitigate CVE-2026-89642

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins