CVE-2026-89609
Received Received - Intake

ecryptfs Message Context List Race Condition

Vulnerability report for CVE-2026-89609, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ecryptfs: hold msg ctx list lock when cleaning daemon queue ecryptfs_exorcise_daemon() drops queued messages from a dying daemon without holding ecryptfs_msg_ctx_lists_mux, but ecryptfs_msg_ctx_alloc_to_free() requires that lock. Take the list lock while moving the queued contexts back to the free list to avoid racing with other global msg ctx list users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux_kernel ecryptfs *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a race condition in the eCryptfs filesystem. The issue occurs when the function ecryptfs_exorcise_daemon() removes queued messages from a dying daemon without holding the ecryptfs_msg_ctx_lists_mux lock. Another function, ecryptfs_msg_ctx_alloc_to_free(), requires this lock to be held. The fix is to hold the lock while moving queued contexts back to the free list to prevent race conditions with other users of the global message context list.

Detection Guidance

This vulnerability is specific to the Linux kernel's ecryptfs module and does not have direct network-based detection methods. You can check if your system is affected by verifying the kernel version and ecryptfs module behavior. Use commands like 'uname -a' to check the kernel version and 'lsmod | grep ecryptfs' to confirm if the module is loaded.

Impact Analysis

This vulnerability could lead to memory corruption or unexpected behavior in the eCryptfs filesystem. If exploited, it might cause system instability, crashes, or unauthorized access to sensitive data stored in encrypted filesystems. Users relying on eCryptfs for secure data storage could face data leaks or corruption.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by potentially exposing encrypted data to unauthorized access or corruption. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. A successful exploit could violate these regulations, leading to legal and financial penalties.

Mitigation Strategies

Update your Linux kernel to the latest stable version that includes the fix for this vulnerability. Monitor kernel security advisories and apply patches promptly. If you cannot update immediately, consider disabling the ecryptfs module if it is not in use with 'modprobe -r ecryptfs'.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89609. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart