Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-89989
Published: September 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of error return values in validate_hash_algo() in IMA appraisal when processing a dentry path that exceeds the buffer. A local user can trigger an extended attribute operation that causes dentry_path() to return an error pointer to cause a denial of service.
Affected software
How to mitigate CVE-2026-89989
External References
- https://git.kernel.org/stable/c/0de5b525c0cd7d202848b8adfde3c01c287fb1a6
- https://git.kernel.org/stable/c/30b5c0e17dcad72b6b2f987319aa645570e6376d
- https://git.kernel.org/stable/c/8861f6d5c0678a7c5089c7b272509fc5931b8437
- https://git.kernel.org/stable/c/9e69d683ebd7def04557fe758ff123105d7d9840
- https://git.kernel.org/stable/c/d62a84a78de5f29c642fa3bd4eee072ba7289cb4
- https://git.kernel.org/stable/c/d6fade89903c8fd0af6c956242aec8b927040e02
- https://git.kernel.org/stable/c/f8a2f2a4602318eb93d49d27fd0d0fdaab17edde