« Volver al listado

CVE-2026-89997

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

dm: fix resume-vs-remove race

If the user issues the resume ioctl and the remove ioctl at the same time, it may be possible that the device is resumed after it is suspended in __dm_destroy. The result is that the table is destroyed without calling the postsuspend method.

Dm targets expect that they may be removed only after the postsuspend method method was called. If we break this expectation, it can cause misbehavior in various targets. For example - in the dm-integrity target, the reboot notifier is not unregistered, leading to use-after-free.

Leer descripción completaMostrar menos

Fix this bug by refusing to resume if the device is being destroyed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89997",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
              "lessThan": "9757367bcf1d5d2c50b94d005abca21f3eedd7c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
              "lessThan": "1ede2bce2bd640605df83db1356fd727159bc9ed",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
              "lessThan": "3f04e6520d9a53adb1d1daf4dc5d31a60fc77d1f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
              "lessThan": "94f3d399c1ddba763c1c5a6501f7375d533d789f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
              "lessThan": "3b59530b14fde693e41d8e39bc326df6cbf07b76",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
              "lessThan": "36177beff2a9df035991ad8d16ccf8d363ed93ee",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
              "lessThan": "94380ecd5ff9b2a2b9f6e8a0b5c465159ccfaf71",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
              "lessThan": "44b43ec132f1cf3275ecc182d0c82f50c3c4c3d5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "305b06f7334dd43bc952b525d7232f4cae7c3818",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2.6.35.4",
              "lessThan": "2.6.36",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/md/dm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.36"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.36",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/md/dm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:10.933",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1ede2bce2bd640605df83db1356fd727159bc9ed",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/36177beff2a9df035991ad8d16ccf8d363ed93ee",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3b59530b14fde693e41d8e39bc326df6cbf07b76",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3f04e6520d9a53adb1d1daf4dc5d31a60fc77d1f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/44b43ec132f1cf3275ecc182d0c82f50c3c4c3d5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/94380ecd5ff9b2a2b9f6e8a0b5c465159ccfaf71",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/94f3d399c1ddba763c1c5a6501f7375d533d789f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9757367bcf1d5d2c50b94d005abca21f3eedd7c3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm: fix resume-vs-remove race\n\nIf the user issues the resume ioctl and the remove ioctl at the same\ntime, it may be possible that the device is resumed after it is suspended\nin __dm_destroy. The result is that the table is destroyed without\ncalling the postsuspend method.\n\nDm targets expect that they may be removed only after the postsuspend\nmethod method was called. If we break this expectation, it can cause\nmisbehavior in various targets. For example - in the dm-integrity target,\nthe reboot notifier is not unregistered, leading to use-after-free.\n\nFix this bug by refusing to resume if the device is being destroyed."
    }
  ],
  "lastModified": "2026-09-17T10:17:05.510",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}