CVE-2026-89992
Last modified
CVE-2026-89992 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: cpuidle: dt_idle_genpd: kfree() the original name allocation dt_idle_pd_alloc() kasprintf()s the full node path, then points pd->name at kbasename() of that string. dt_idle_pd_free() kfree()s pd->name, which is no longer the start of the allocation. Copy the basename instead..
Description
In the Linux kernel, the following vulnerability has been resolved: cpuidle: dt_idle_genpd: kfree() the original name allocation dt_idle_pd_alloc() kasprintf()s the full node path, then points pd->name at kbasename() of that string. dt_idle_pd_free() kfree()s pd->name, which is no longer the start of the allocation. Copy the basename instead.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 9d976d6721dfb525b81ce981e1363c70c0975aab, < 1312ae33b91430ec99e69cd3d47f0e50a4ebf54b; >= 9d976d6721dfb525b81ce981e1363c70c0975aab, < a38caa9ed0d5c61c17d88393b14b292199289c1f; >= 9d976d6721dfb525b81ce981e1363c70c0975aab, < 09d002c8fb0261d35ce9d8a705de5db034ee90b8; >= 9d976d6721dfb525b81ce981e1363c70c0975aab, < b519dfce1998c323e54a56f911cf708d9ba0e076; >= 9d976d6721dfb525b81ce981e1363c70c0975aab, < 3394c7ba23336bdb7ece29127130fd01731d42d8; >= 9d976d6721dfb525b81ce981e1363c70c0975aab, < 2b0ac85512b7f67479127b2713254490662eb13d |
| Linux | Linux | 5.18 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89992?
How severe is CVE-2026-89992?
How do I fix CVE-2026-89992?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89986In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89987In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89988In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89989In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89990In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-89991In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89993In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89994In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89995In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-89996In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89997In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89998In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-89992?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
