PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-89793 Linux CVE debrief

A vulnerability in the Linux kernel's ublk subsystem allows an unprivileged userspace daemon to corrupt kernel-written ABI data in the per-queue command buffer. The ublk_ch_mmap() function rejects mmap requests with VM_WRITE set but fails to clear VM_MAYWRITE on the resulting read-only mapping. This enables a daemon to upgrade a PROT_READ mapping to PROT_WRITE via mprotect(), potentially causing data corruption.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-10-05
Advisory published
2026-09-16
Advisory updated
2026-10-05

Who should care

Linux kernel developers, administrators, and security teams should assess exposure and prioritize verification of affected systems, especially those with unprivileged userspace daemons interacting with ublk devices.

Why it matters

CVE-2026-89793 is a vulnerability in the Linux kernel's ublk subsystem that allows an unprivileged userspace daemon to corrupt kernel-written ABI data. Linux kernel developers and administrators should assess exposure and prioritize verification of affected systems.

  • Unprivileged daemon can corrupt kernel-written ABI data in the per-queue command buffer.
  • Potential data corruption or unauthorized modifications to kernel data.
  • Verification of affected systems and patch application are required to prevent exploitation.
  • Monitoring for potential data corruption or unauthorized modifications to kernel data is necessary.

Technical summary

The ublk_ch_mmap() function in the Linux kernel fails to clear VM_MAYWRITE on read-only ublk char device mappings. This allows an unprivileged userspace daemon to mmap the per-queue command buffer with PROT_READ and then upgrade it to PROT_WRITE via mprotect(). The command buffer holds struct ublksrv_io_desc entries that are kernel-written ABI; a writable mapping lets the daemon corrupt fields such as addr, op_flags, nr_sectors, and start_sector.

Defensive priority

Linux kernel developers and administrators should assess exposure and prioritize verification of affected systems, especially those with unprivileged userspace daemons interacting with ublk devices.

Recommended defensive actions

  • Review and apply the provided Linux kernel patches to address the vulnerability.
  • Assess exposure of Linux kernel deployments, especially those with unprivileged userspace daemons interacting with ublk devices.
  • Verify that affected systems are upgraded to a patched version of the Linux kernel.
  • Monitor for potential data corruption or unauthorized modifications to kernel data.
  • Perform a thorough review of system logs to detect any potential exploitation attempts.
  • Implement additional monitoring and logging to track access to affected systems.
  • Conduct a thorough asset inventory to identify all systems that may be affected by this vulnerability.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected components. The Linux kernel source code references are provided, but specific affected versions are not explicitly mentioned.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-89793 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-89793

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-89793 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89793

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5befd06a72216869b607cf7724a4f16c6a2d3999

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6e2b571b0a54755b06e092501913e1dfefe75d6c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/be41733c24be58e2a1ef718c80fafdfb98a40d5e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e373c1acdbcf88cec533ece9f589020adaed0a78

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fa5e1bc673ca59722608af67b27e65dba0c97926

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.