Heap-based buffer overflow in Linux kernel - CVE-2026-89497
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to write past the end of an allocated keyword buffer.
The vulnerability exists due to a heap-based buffer overflow in orangefs_prepare_cdm_array() when processing a client debug entry that begins with a space. A local user can supply a client debug entry beginning with a space to write past the end of an allocated keyword buffer.