CVE-2026-89498
Last modified
CVE-2026-89498 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: orangefs: fix double-free of trailer_buf on readdir copy failure On a readdir downcall, orangefs_devreq_write_iter() frees op->downcall.trailer_buf with vfree() when copy_from_iter_full() fails, but does not clear the pointer before goto Efault. The waiter in do_readdir() is then woken with a negative status and frees the same pointer again on its r < 0 path, causing a deterministic double-free. A client holding /dev/pvfs2-req triggers it by sending a readdir downcall whose declared trailer_size exceeds the bytes it supplies. Clear the pointer after freeing so the readdir-side vfree() becomes a no-op.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: orangefs: fix double-free of trailer_buf on readdir copy failure On a readdir downcall, orangefs_devreq_write_iter() frees op->downcall.trailer_buf with vfree() when copy_from_iter_full() fails, but does not clear the pointer before goto Efault. The waiter in do_readdir() is then woken with a negative status and frees the same pointer again on its r < 0 path, causing a deterministic double-free. A client holding /dev/pvfs2-req triggers it by sending a readdir downcall whose declared trailer_size exceeds the bytes it supplies. Clear the pointer after freeing so the readdir-side vfree() becomes a no-op.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 382f4581e67f57209c7aa67e39f26ba076306a2e, < 712c4235fcc73c11a2f1d59a499d489e49c374a4; >= 382f4581e67f57209c7aa67e39f26ba076306a2e, < 433c2e470053cc9c712314d3d8c3dfbc862d68eb; >= 382f4581e67f57209c7aa67e39f26ba076306a2e, < 6e5924644ef4bce06a3cbb7cb841a8bbfdfc03ad; >= 382f4581e67f57209c7aa67e39f26ba076306a2e, < 9c9eacc47c618ed6d7d35fe75a40d294c8cdbffa; >= 382f4581e67f57209c7aa67e39f26ba076306a2e, < 2f5454a25127854c232fde5d1d65d16fbcd42d43; >= 382f4581e67f57209c7aa67e39f26ba076306a2e, < f796f38a324e89547738f4b70cc33be5be2bc6da; >= 382f4581e67f57209c7aa67e39f26ba076306a2e, < 519f4146b8b8c5f20c2ad01913acd6df2df8fc8e; >= 382f4581e67f57209c7aa67e39f26ba076306a2e, < f574296be7f46eb60beca851240b526df232f480 |
| Linux | Linux | 4.12 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89498?
How severe is CVE-2026-89498?
How do I fix CVE-2026-89498?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89492In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-89493In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-89494In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-89495In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-89496In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89497In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89499In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-8950Same-origin policy bypass in the Networking: HTTP component.…9.3
- CVE-2026-89500In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89501In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89502In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89503In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-89498?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
