CVE-2026-89500
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
03/10/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page<br />
<br />
Discarding a cached reader page after a concurrent ring buffer resize<br />
uses the new global subbuf_order for the free_pages() call. This<br />
mismatched order may crashes the kernel or leaks memory because the cached<br />
page was allocated under the old size.<br />
<br />
Save the actual free_page order alongside the page address to ensure we<br />
always refer to the correct value and do not rely on the potentially<br />
stalled cpu_buffer->subbuf_order value. The simplest is to make<br />
free_page a buffer_data_read_page which already covers exactly what we<br />
need: a page address and a page order.
Impacto
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA


