« Volver al listado

CVE-2026-89745

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

debugfs: Fix lockdown check for mmap_prepare

Commit 651fdda8406d ("relay: update relay to use mmap_prepare") changed the `mmap` file operation to `mmap_prepare` for relayfs, but the lockdown check in debugfs was not updated accordingly.

This prevents debugfs from being locked down when the kernel is in integrity mode if a file uses `mmap_prepare` but not `mmap`.

Since the conversion to `mmap_prepare` across the kernel is not yet complete, update the lockdown check to look for both `mmap` and `mmap_prepare` to ensure comprehensive coverage.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89745",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "651fdda8406d42a5004c5c79f269540a85d6a1ab",
              "lessThan": "e7f6a6b5741d16fdac7adaecbe0fa52ae756f208",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "651fdda8406d42a5004c5c79f269540a85d6a1ab",
              "lessThan": "f81808de37338aac8e167f99bfae647b1b835c70",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/debugfs/file.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/debugfs/file.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:20:05.260",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/e7f6a6b5741d16fdac7adaecbe0fa52ae756f208",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f81808de37338aac8e167f99bfae647b1b835c70",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndebugfs: Fix lockdown check for mmap_prepare\n\nCommit 651fdda8406d (\"relay: update relay to use mmap_prepare\")\nchanged the `mmap` file operation to `mmap_prepare` for relayfs, but\nthe lockdown check in debugfs was not updated accordingly.\n\nThis prevents debugfs from being locked down when the kernel is in\nintegrity mode if a file uses `mmap_prepare` but not `mmap`.\n\nSince the conversion to `mmap_prepare` across the kernel is not yet\ncomplete, update the lockdown check to look for both `mmap` and\n`mmap_prepare` to ensure comprehensive coverage."
    }
  ],
  "lastModified": "2026-09-11T20:20:05.260",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}