« Volver al listado

CVE-2026-89770

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

iomap: don't free integrity payload that doesn't exist

fs_bio_integrity_alloc might not allocate a bio integrity payload if PI verification is disabled on the block device. Check for that case before calling fs_bio_integrity_free in iomap_bio_read_folio_range_sync to avoid a NULL pointer dereferences.

Make the branch cover the PI verification as well - while fs_bio_integrity_verify works without an integrity payload, it requires one to actually do useful work.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89770",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0b10a370529cbd7b918c1eef43d409e43d9e0b78",
              "lessThan": "65651f1001aa3638909bc58c7b2b46160692757b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0b10a370529cbd7b918c1eef43d409e43d9e0b78",
              "lessThan": "8a8685b32c0718cc7b2cb4d6202e5a5b8e0a8e2d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/iomap/bio.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/iomap/bio.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:20:08.353",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/65651f1001aa3638909bc58c7b2b46160692757b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8a8685b32c0718cc7b2cb4d6202e5a5b8e0a8e2d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niomap: don't free integrity payload that doesn't exist\n\nfs_bio_integrity_alloc might not allocate a bio integrity payload if PI\nverification is disabled on the block device.  Check for that case before\ncalling fs_bio_integrity_free in iomap_bio_read_folio_range_sync to\navoid a NULL pointer dereferences.\n\nMake the branch cover the PI verification as well - while\nfs_bio_integrity_verify works without an integrity payload, it requires\none to actually do useful work."
    }
  ],
  "lastModified": "2026-09-11T20:20:08.353",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}