CVE-2026-89997
In the Linux kernel, the following vulnerability has been resolved:
dm: fix resume-vs-remove race
If the user issues the resume ioctl and the remove ioctl at the same time, it may be possible that the device is resumed after it is suspended in __dm_destroy. The result is that the table is destroyed without calling the postsuspend method.
Dm targets expect that they may be removed only after the postsuspend method method was called. If we break this expectation, it can cause misbehavior in various targets. For example - in the dm-integrity target, the reboot notifier is not unregistered, leading to use-after-free.
Leer descripción completaMostrar menos
Fix this bug by refusing to resume if the device is being destroyed.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation60 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1ede2bce2bd640605df83db1356fd727159bc9ed
- https://git.kernel.org/stable/c/36177beff2a9df035991ad8d16ccf8d363ed93ee
- https://git.kernel.org/stable/c/3b59530b14fde693e41d8e39bc326df6cbf07b76
- https://git.kernel.org/stable/c/3f04e6520d9a53adb1d1daf4dc5d31a60fc77d1f
- https://git.kernel.org/stable/c/44b43ec132f1cf3275ecc182d0c82f50c3c4c3d5
- https://git.kernel.org/stable/c/94380ecd5ff9b2a2b9f6e8a0b5c465159ccfaf71
- https://git.kernel.org/stable/c/94f3d399c1ddba763c1c5a6501f7375d533d789f
- https://git.kernel.org/stable/c/9757367bcf1d5d2c50b94d005abca21f3eedd7c3
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89997",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
"lessThan": "9757367bcf1d5d2c50b94d005abca21f3eedd7c3",
"versionType": "git"
},
{
"status": "affected",
"version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
"lessThan": "1ede2bce2bd640605df83db1356fd727159bc9ed",
"versionType": "git"
},
{
"status": "affected",
"version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
"lessThan": "3f04e6520d9a53adb1d1daf4dc5d31a60fc77d1f",
"versionType": "git"
},
{
"status": "affected",
"version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
"lessThan": "94f3d399c1ddba763c1c5a6501f7375d533d789f",
"versionType": "git"
},
{
"status": "affected",
"version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
"lessThan": "3b59530b14fde693e41d8e39bc326df6cbf07b76",
"versionType": "git"
},
{
"status": "affected",
"version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
"lessThan": "36177beff2a9df035991ad8d16ccf8d363ed93ee",
"versionType": "git"
},
{
"status": "affected",
"version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
"lessThan": "94380ecd5ff9b2a2b9f6e8a0b5c465159ccfaf71",
"versionType": "git"
},
{
"status": "affected",
"version": "3f77316de0ec0fd208467fbee8d9edc70e2c73b2",
"lessThan": "44b43ec132f1cf3275ecc182d0c82f50c3c4c3d5",
"versionType": "git"
},
{
"status": "affected",
"version": "305b06f7334dd43bc952b525d7232f4cae7c3818",
"versionType": "git"
},
{
"status": "affected",
"version": "2.6.35.4",
"lessThan": "2.6.36",
"versionType": "semver"
}
],
"programFiles": [
"drivers/md/dm.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.36"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.36",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.51",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.5",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/md/dm.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-16T11:17:10.933",
"references": [
{
"url": "https://git.kernel.org/stable/c/1ede2bce2bd640605df83db1356fd727159bc9ed",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/36177beff2a9df035991ad8d16ccf8d363ed93ee",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3b59530b14fde693e41d8e39bc326df6cbf07b76",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3f04e6520d9a53adb1d1daf4dc5d31a60fc77d1f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/44b43ec132f1cf3275ecc182d0c82f50c3c4c3d5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/94380ecd5ff9b2a2b9f6e8a0b5c465159ccfaf71",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/94f3d399c1ddba763c1c5a6501f7375d533d789f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9757367bcf1d5d2c50b94d005abca21f3eedd7c3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm: fix resume-vs-remove race\n\nIf the user issues the resume ioctl and the remove ioctl at the same\ntime, it may be possible that the device is resumed after it is suspended\nin __dm_destroy. The result is that the table is destroyed without\ncalling the postsuspend method.\n\nDm targets expect that they may be removed only after the postsuspend\nmethod method was called. If we break this expectation, it can cause\nmisbehavior in various targets. For example - in the dm-integrity target,\nthe reboot notifier is not unregistered, leading to use-after-free.\n\nFix this bug by refusing to resume if the device is being destroyed."
}
],
"lastModified": "2026-09-17T10:17:05.510",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}