Missing Authorization in Linux kernel - CVE-2026-89560

 

Missing Authorization in Linux kernel - CVE-2026-89560

Published: September 12, 2026


Vulnerability identifier: #VU149250
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89560
CWE-ID: CWE-862
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass Landlock filesystem access restrictions.

The vulnerability exists due to improper access control in Landlock whiteout creation checks when creating whiteout objects with mknod(2) or renameat2(2) using RENAME_WHITEOUT. A local user can create a whiteout object despite denied required Landlock access rights to bypass Landlock filesystem access restrictions.

Normal renames within layered OverlayFS mounts are not affected.


Affected software

Linux kernel

How to mitigate CVE-2026-89560

Install security update from vendor's repository.


External References

Related Security Bulletins