Incomplete cleanup in Linux kernel - CVE-2026-89815
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to incomplete cleanup of restore state in ttm_pool_restore_and_alloc() in the DRM TTM memory-management component when completing a backup restore operation. A local user can initiate subsequent backup and restore flows to compromise confidentiality, integrity, and availability.