CVE-2026-89503
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
03/10/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()<br />
<br />
ring_buffer_alloc_read_page() is racy with ring_buffer_subbuf_order_set,<br />
it can allocate a reader page with an outdated order. This isn&#39;t a big<br />
issue, the user can still re-allocate a new reader page and try again.<br />
<br />
However, what is more problematic is if the value of subbuf_order<br />
changes in the middle of ring_buffer_alloc_read_page(). In that case,<br />
bpage->order might not match the actual allocated memory.<br />
<br />
Use bpage->order for the allocation to prevent this race.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH


