Race condition in Linux kernel - CVE-2026-89540
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a resource leak.
The vulnerability exists due to an initialization race condition in the use-gss-proxy proc entry initialization when writing to the newly published proc entry before gssp_lock is initialized. A local user can win the initialization race and write to the proc entry to cause a resource leak.
The race window can widen when the auth_rpcgss module is loaded for live network namespaces.