CVE-2026-89605: Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ecryptfs: release message context on send failure ecryptfs_send_message_locked() moves a message context from the free list to the allocated list before sending the request to the userspace daemon. If ecryptfs_send_miscdev() fails, the context is left on the allocated list and cannot be reused. Move it back to the free list on failure and clear the caller's pointer.

Affected products

  • Linux Linux: from 2.6.26, before 5.10.270 (fixed in 5.10.270); from 5.11, before 5.15.221 (fixed in 5.15.221); from 5.16, before 6.1.188 (fixed in 6.1.188); from 6.2, before 6.6.157 (fixed in 6.6.157); from 6.7, before 6.12.109 (fixed in 6.12.109); from 6.13, before 6.18.50 (fixed in 6.18.50); …

Published 2026-09-11. Last modified 2026-09-14.