CVE-2026-89992: Linux

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: cpuidle: dt_idle_genpd: kfree() the original name allocation dt_idle_pd_alloc() kasprintf()s the full node path, then points pd->name at kbasename() of that string. dt_idle_pd_free() kfree()s pd->name, which is no longer the start of the allocation. Copy the basename instead.

Affected products

  • Linux Linux: from 5.18, before 6.1.188 (fixed in 6.1.188); from 6.2, before 6.6.157 (fixed in 6.6.157); from 6.7, before 6.12.110 (fixed in 6.12.110); from 6.13, before 6.18.51 (fixed in 6.18.51); from 6.19, before 7.2.5 (fixed in 7.2.5)

Published 2026-09-16. Last modified 2026-09-16.