CVE-2026-89498: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: orangefs: fix double-free of trailer_buf on readdir copy failure On a readdir downcall, orangefs_devreq_write_iter() frees op->downcall.trailer_buf with vfree() when copy_from_iter_full() fails, but does not clear the pointer before goto Efault. The waiter in do_readdir() is then woken with a negative status and frees the same pointer again on its r < 0 path, causing a deterministic double-free. A client holding /dev/pvfs2-req triggers it by sending a readdir downcall whose declared trailer_size exceeds the bytes it supplies. Clear the pointer after freeing so the readdir-side vfree() becomes a no-op.
Affected products
- Linux Linux: from 4.12, before 5.10.270 (fixed in 5.10.270); from 5.11, before 5.15.221 (fixed in 5.15.221); from 5.16, before 6.1.188 (fixed in 6.1.188); from 6.2, before 6.6.157 (fixed in 6.6.157); from 6.7, before 6.12.109 (fixed in 6.12.109); from 6.13, before 6.18.50 (fixed in 6.18.50); …
Published 2026-09-11. Last modified 2026-09-14.