CVE-2026-89643
Received Received - Intake

Linux Kernel fsnotify Rule Reference Leak

Vulnerability report for CVE-2026-89643, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: audit: avoid dropping live tree ref on fsnotify rule autoremove audit_del_rule() is used for both netlink deletion templates and internal fsnotify autoremove. The former passes a parsed template which owns a temporary tree reference; the latter passes the installed entry itself. The unconditional audit_put_tree() at the end of audit_del_rule() assumes the template case. For mixed AUDIT_DIR plus AUDIT_EXE rules, an fsnotify autoremove event therefore drops the installed rule's live tree reference. Repeating this across rules sharing the same tree can free the tree while another rule still references it, and a later autoremove dereferences the freed pathname while comparing rules. Move the temporary-tree put to audit_rule_change(), the caller that owns deletion templates. Keep it in the AUDIT_DEL_RULE cleanup so both successful deletion and -ENOENT still release the parser-owned tree. [PM: dropped unnecessary comment for line length reasons]

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the audit subsystem where a live tree reference is incorrectly dropped during fsnotify rule autoremove operations. Specifically, audit_del_rule() improperly releases a tree reference for installed rules when handling mixed AUDIT_DIR and AUDIT_EXE rules, potentially leading to use-after-free issues when the tree is freed while still in use.

Detection Guidance

This vulnerability is specific to the Linux kernel's audit subsystem and does not have network-based detection methods. To detect it, check your kernel version and audit logs for fsnotify-related errors or crashes. Commands: uname -a to check kernel version, dmesg | grep audit to review audit subsystem logs, and journalctl -k | grep audit for systemd-based systems.

Impact Analysis

This vulnerability could lead to system instability or crashes due to dereferencing freed memory. An attacker with local access might exploit this to cause denial-of-service conditions or escalate privileges by manipulating audit rules and fsnotify events.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a Linux kernel issue related to audit rule management and fsnotify operations, which does not involve data handling, privacy, or security controls typically addressed by these regulations.

Mitigation Strategies

Apply the latest kernel update from your Linux distribution to patch the vulnerability. If immediate patching is not possible, avoid using mixed AUDIT_DIR plus AUDIT_EXE rules in audit configurations to reduce risk. Monitor audit logs for fsnotify-related errors as a potential indicator of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89643. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart