Improper access control in Linux kernel - CVE-2026-89793
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to corrupt kernel-written command-buffer fields.
The vulnerability exists due to improper access control in ublk_ch_mmap() when upgrading a read-only ublk character-device mapping with mprotect(). A local user can change the mapping to writable and modify per-queue command-buffer entries to corrupt kernel-written command-buffer fields.
Affected software
How to mitigate CVE-2026-89793
External References
- https://git.kernel.org/stable/c/5befd06a72216869b607cf7724a4f16c6a2d3999
- https://git.kernel.org/stable/c/6e2b571b0a54755b06e092501913e1dfefe75d6c
- https://git.kernel.org/stable/c/be41733c24be58e2a1ef718c80fafdfb98a40d5e
- https://git.kernel.org/stable/c/e373c1acdbcf88cec533ece9f589020adaed0a78
- https://git.kernel.org/stable/c/fa5e1bc673ca59722608af67b27e65dba0c97926