Resource exhaustion in Linux kernel - CVE-2026-89604
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the efivarfs statfs() handler when repeatedly invoking statfs() on the efivarfs mount point. A local user can flood the QueryVariableInfo() runtime service with statfs() calls to cause a denial of service.
On x86 systems with a variable store backed by SMM, each runtime-service entry requires a rendezvous of all CPUs.