Improper locking in Linux kernel - CVE-2026-89609
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to trigger a race condition.
The vulnerability exists due to improper locking in ecryptfs_exorcise_daemon() when cleaning queued messages from a dying daemon. A local user can move queued message contexts to the free list without holding the required global list lock to trigger a race condition.