« Volver al listado

CVE-2026-89998

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

dm: fix race when loading and unloading a table

If the userspace calls two concurrent table load ioctls and one of them succeeds and the other fails, there is a race condition because dm_setup_md_queue walks &md->table_devices without any lock. If the walk races with dm_table_destroy -> free_devices -> dm_put_table_device, there is access to invalid memory.

Fix this race by extending the lock over the list walk.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de escalada de privilegios local en el kernel de Linux por race condition sin bloqueo. Acceso local con privilegios normales (PR:L) permite provocar DoS o lectura de memoria de kernel.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89998",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "773bfda35c9511734d7f898e2ee73cd60d2a3f38",
              "lessThan": "b02e35b81176c7d61dd441cc7a2e5c324a82444b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a581b72169968f4154b5793828f3bc28b258b35",
              "lessThan": "0ea6e5ad4a5817e91f11b4cc1e022e575ed2e7ca",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a581b72169968f4154b5793828f3bc28b258b35",
              "lessThan": "a1af1884c960b98c621b6fe2fea1216b78c02152",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a581b72169968f4154b5793828f3bc28b258b35",
              "lessThan": "af1f32ccf8051f4691ced11feb452b9d13561727",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a581b72169968f4154b5793828f3bc28b258b35",
              "lessThan": "00ad6f9ed27f91925d4d3fb7aab50a60d774f998",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a581b72169968f4154b5793828f3bc28b258b35",
              "lessThan": "5380c7f6335cc6d77eb77d065105e81155c4d9d3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "600593707c239bb99486925d65540a5020bc1e58",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.1.2",
              "lessThan": "6.1.188",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.0.16",
              "lessThan": "6.1",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/md/dm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/md/dm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:11.060",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/00ad6f9ed27f91925d4d3fb7aab50a60d774f998",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/0ea6e5ad4a5817e91f11b4cc1e022e575ed2e7ca",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5380c7f6335cc6d77eb77d065105e81155c4d9d3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a1af1884c960b98c621b6fe2fea1216b78c02152",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/af1f32ccf8051f4691ced11feb452b9d13561727",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b02e35b81176c7d61dd441cc7a2e5c324a82444b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm: fix race when loading and unloading a table\n\nIf the userspace calls two concurrent table load ioctls and one of them\nsucceeds and the other fails, there is a race condition because\ndm_setup_md_queue walks &md->table_devices without any lock. If the walk\nraces with dm_table_destroy -> free_devices -> dm_put_table_device, there\nis access to invalid memory.\n\nFix this race by extending the lock over the list walk."
    }
  ],
  "lastModified": "2026-09-17T10:17:05.657",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}