CVE-2026-89500

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
03/10/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page<br /> <br /> Discarding a cached reader page after a concurrent ring buffer resize<br /> uses the new global subbuf_order for the free_pages() call. This<br /> mismatched order may crashes the kernel or leaks memory because the cached<br /> page was allocated under the old size.<br /> <br /> Save the actual free_page order alongside the page address to ensure we<br /> always refer to the correct value and do not rely on the potentially<br /> stalled cpu_buffer-&gt;subbuf_order value. The simplest is to make<br /> free_page a buffer_data_read_page which already covers exactly what we<br /> need: a page address and a page order.