Missing Authorization in Linux kernel - CVE-2026-89560
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to bypass Landlock filesystem access restrictions.
The vulnerability exists due to improper access control in Landlock whiteout creation checks when creating whiteout objects with mknod(2) or renameat2(2) using RENAME_WHITEOUT. A local user can create a whiteout object despite denied required Landlock access rights to bypass Landlock filesystem access restrictions.
Normal renames within layered OverlayFS mounts are not affected.