CVE-2026-89600
Received Received - Intake

Use-After-Free in Linux Kernel Fanotify

Vulnerability report for CVE-2026-89600, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: fanotify: fix use-after-free of file range info fsnotify_pre_content() builds its file_range on the triggering task's stack. fanotify_alloc_perm_event() saves a pointer to range.pos in the heap-allocated permission event so copy_range_info_to_user() can report the offset later. The event reader can set the event state to FAN_EVENT_REPORTED and then sleep while preparing the file descriptor. If a signal interrupts the triggering task at that point, fanotify_get_response() changes the state to FAN_EVENT_CANCELED and returns. This unwinds the file_range stack frame while the reader still owns the event. The reader then dereferences pevent->ppos and copies the stale stack value to userspace. KASAN reported: BUG: KASAN: use-after-free in fanotify_read+0x293e/0x2970 Read of size 8 at addr ffff88811434fc50 by task fanotify_inotif/95 Call Trace: fanotify_read+0x293e/0x2970 vfs_read+0x177/0xa20 ksys_read+0xf7/0x1c0 do_syscall_64+0xf9/0x540 entry_SYSCALL_64_after_hwframe+0x77/0x7f Store the range position directly in the permission event and use FANOTIFY_NO_RANGE when range information is unavailable. The event remains alive until the reader finishes, so the reported offset no longer depends on the triggering task's stack.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in the Linux kernel's fanotify feature. It occurs when a file range info structure is accessed after its memory has been freed. The issue arises because a pointer to stack memory is stored in a heap-allocated event, and if the event state changes due to a signal interrupting the triggering task, the stack frame is unwound while the event reader still holds a reference to the stale pointer.

Detection Guidance

This vulnerability is specific to the Linux kernel's fanotify functionality and may be detected by checking kernel logs for KASAN reports or use-after-free errors related to fanotify_read. Monitor system logs for errors like 'BUG: KASAN: use-after-free in fanotify_read' or similar traces.

Impact Analysis

This vulnerability could allow an attacker to read or write to freed memory, potentially causing system crashes, data corruption, or privilege escalation. It specifically affects systems using fanotify, which is commonly used for file access monitoring.

Compliance Impact

This vulnerability is a use-after-free flaw in the Linux kernel's fanotify feature, which could lead to memory corruption or information disclosure. While not directly tied to compliance standards like GDPR or HIPAA, such vulnerabilities may impact systems handling sensitive data by potentially exposing or corrupting information during processing.

Mitigation Strategies

Apply the latest Linux kernel patches that address this issue. If immediate patching is not possible, consider disabling fanotify features if they are not required, or restrict access to fanotify-related operations until the patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89600. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart