CVE-2026-89498: vulnerability in Linux
orangefs: fix double-free of trailer_buf on readdir copy failure
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 93% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
orangefs: fix double-free of trailer_buf on readdir copy failure
On a readdir downcall, orangefs_devreq_write_iter() frees
op->downcall.trailer_buf with vfree() when copy_from_iter_full() fails,
but does not clear the pointer before goto Efault. The waiter in
do_readdir() is then woken with a negative status and frees the same
pointer again on its r < 0 path, causing a deterministic double-free.
A client holding /dev/pvfs2-req triggers it by sending a readdir
downcall whose declared trailer_size exceeds the bytes it supplies.
Clear the pointer after freeing so the readdir-side vfree() becomes a
no-op.
Affected products
Linux · LinuxRelated CVEs — Linux
In the same product, most dangerous first.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
References
https://git.kernel.org/stable/c/2f5454a25127854c232fde5d1d65d16fbcd42d43https://git.kernel.org/stable/c/433c2e470053cc9c712314d3d8c3dfbc862d68ebhttps://git.kernel.org/stable/c/519f4146b8b8c5f20c2ad01913acd6df2df8fc8ehttps://git.kernel.org/stable/c/6e5924644ef4bce06a3cbb7cb841a8bbfdfc03adhttps://git.kernel.org/stable/c/712c4235fcc73c11a2f1d59a499d489e49c374a4https://git.kernel.org/stable/c/9c9eacc47c618ed6d7d35fe75a40d294c8cdbffahttps://git.kernel.org/stable/c/f574296be7f46eb60beca851240b526df232f480https://git.kernel.org/stable/c/f796f38a324e89547738f4b70cc33be5be2bc6da