CVE-2026-89604
Received Received - Intake

Rate-limited statfs() Handler in Linux Kernel efivarfs

Vulnerability report for CVE-2026-89604, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: efivarfs: Rate limit statfs() handler Ravi reports that statfs() may be called by unprivileged users on the efivarfs mount point, which may result in a flood of calls to the QueryVariableInfo() runtime service. These calls are disproportionately costly on x86 systems where the variable store is backed by SMM, as each SMM entry requires a rendez-vous of all the CPUs. So rate limit the calls to QueryVariableInfo() at twice per second, and return the most recently obtained value for calls that are elided.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves an unprivileged user triggering excessive calls to the statfs() function on the efivarfs mount point. These calls invoke the costly QueryVariableInfo() service, especially on x86 systems where the variable store uses SMM, causing CPU rendez-vous overhead. The fix introduces rate limiting to prevent abuse.

Detection Guidance

This vulnerability can be detected by monitoring for excessive statfs() calls on the efivarfs mount point. Check for high CPU usage or repeated calls to QueryVariableInfo() by unprivileged users. Use commands like 'mount | grep efivarfs' to locate the mount point and 'dmesg' or 'journalctl' to review system logs for unusual activity.

Impact Analysis

An attacker could exploit this to cause a denial-of-service by flooding the system with statfs() calls, leading to high CPU usage and potential system slowdowns or crashes. Systems with efivarfs mounted are primarily affected.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It involves a rate-limiting issue in the Linux kernel's efivarfs statfs() handler, which could lead to resource exhaustion but does not involve data breaches or unauthorized access to sensitive information.

Mitigation Strategies

Apply the latest Linux kernel patches to address the issue. Limit access to the efivarfs mount point by restricting unprivileged user permissions. Monitor system logs for repeated statfs() calls and consider temporarily disabling efivarfs if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89604. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart