Race condition in Linux kernel - CVE-2026-89823

 

Race condition in Linux kernel - CVE-2026-89823

Published: September 17, 2026


Vulnerability identifier: #VU150462
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89823
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a race condition in drm_dev_register() error handling when a partially registered DRM minor is opened and an ioctl is processed. A local user can open the registered minor and issue an ioctl while device resources are being torn down to compromise confidentiality, integrity, and availability.


Affected software

Linux kernel

How to mitigate CVE-2026-89823

Install security update from vendor's repository.


External References

Related Security Bulletins