From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 62EA3585979 for ; Fri, 11 Sep 2026 19:58:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156721; cv=none; b=RJn/Dlzs2UMCpWQadt7n9P+vyXaTpal8OhRjvnyDyZPhf9d2Pwp+4zdZTI+n7YRghvYDQwV2bXdXLjcbN1sfh6Am+dXhuZsgqSta3XvAD4uHCYjhSFY8MyAEf6qtpgGfG2Cp4C6L9XUMUFy0YUNwkHXedfBVHC1gAnxL/Ltt9+M= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156721; c=relaxed/simple; bh=GcXEhOrP4WOFEc9gU/7wlN02UQAzncBWKS2rCoEr7uY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=oexYH9h6Fwxz1qwFcIFkv1xueYXPNKSt71GSqdcOHNFaTSH1VIpVadlARgxtWE2R+G61B/w9c2jpfxWldoTddrkU6ChLTL4I7aTznhWRq2OapefLDeKs9MFGFOxufv2RwBMEulvSrSMaCUbPgQHysjaX3lprDNuGBRhDssoiVvo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=okpwZKh7; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="okpwZKh7" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 45F001F0089B; Fri, 11 Sep 2026 19:58:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156714; bh=wqA0GTzVZ78kLuAiXnIsffneAUzjRQNl9Shz1uJi/q8=; h=From:To:Cc:Subject:Date:Reply-To; b=okpwZKh7rjYP2JmOEDPPlmAbCvAv2/c0cKFrfEcgI242FZua8QxCuoqzL+E7hPK97 Z1Iis8IXLhie51FzZr7IuUoTbJ15Z/LHXWShqqdUdDS6U11mESr+nzNIX0eptR53TF L5cKQKPadUmeS8IeExUQrC4QqCP9/aZ7m1SINUi0= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89609: ecryptfs: hold msg ctx list lock when cleaning daemon queue Date: Fri, 11 Sep 2026 21:44:58 +0200 Message-ID: <2026091134-CVE-2026-89609-28bd@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2538; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=pDqprPtNTy3sboowhud4j43OVG7vFZQBIIciLUXqMNo=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIvOOrKleavby71vnyfJezp79afNFb3U3RsYUsnZ1X A1pKHzbEcvCIMjEICumyPJlG8/R/RWHFL0MbU/DzGFlAhnCwMUpABMxZ2RYMDFrWder3y9nZn05 v/PbxzAObgtfRYZ5el3X/036Zffx7Y+Np7irbzg/PiQ5EwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ecryptfs: hold msg ctx list lock when cleaning daemon queue ecryptfs_exorcise_daemon() drops queued messages from a dying daemon without holding ecryptfs_msg_ctx_lists_mux, but ecryptfs_msg_ctx_alloc_to_free() requires that lock. Take the list lock while moving the queued contexts back to the free list to avoid racing with other global msg ctx list users. The Linux kernel CVE team has assigned CVE-2026-89609 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.26 with commit f66e883eb6186bc43a79581b67aff7d1a69d0ff1 and fixed in 6.12.109 with commit 7e48afafe7abc275f7b6916613bb18b821e7d94a Issue introduced in 2.6.26 with commit f66e883eb6186bc43a79581b67aff7d1a69d0ff1 and fixed in 6.18.50 with commit 0d9636ecba34bd553ecf19049f7705505aea62fd Issue introduced in 2.6.26 with commit f66e883eb6186bc43a79581b67aff7d1a69d0ff1 and fixed in 7.2.4 with commit 4c02acbe0a2692ca9991c51e62bbe6d6b59dac31 Issue introduced in 2.6.26 with commit f66e883eb6186bc43a79581b67aff7d1a69d0ff1 and fixed in 7.3-rc1 with commit 779972513c2fa8c7938e54976f686091dafff22f Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89609 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/ecryptfs/messaging.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/7e48afafe7abc275f7b6916613bb18b821e7d94a https://git.kernel.org/stable/c/0d9636ecba34bd553ecf19049f7705505aea62fd https://git.kernel.org/stable/c/4c02acbe0a2692ca9991c51e62bbe6d6b59dac31 https://git.kernel.org/stable/c/779972513c2fa8c7938e54976f686091dafff22f