Double free in Linux kernel - CVE-2026-89498
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to trigger a double-free.
The vulnerability exists due to double free in the OrangeFS readdir downcall handling when processing a readdir downcall with a declared trailer size that exceeds the supplied data. A local user can send a readdir downcall with insufficient trailer data to trigger a double-free.