PatchSiren cyber security CVE debrief
CVE-2026-89793 Linux CVE debrief
A vulnerability in the Linux kernel's ublk subsystem allows an unprivileged userspace daemon to corrupt kernel-written ABI data in the per-queue command buffer. The ublk_ch_mmap() function rejects mmap requests with VM_WRITE set but fails to clear VM_MAYWRITE on the resulting read-only mapping. This enables a daemon to upgrade a PROT_READ mapping to PROT_WRITE via mprotect(), potentially causing data corruption.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-10-05
Who should care
Linux kernel developers, administrators, and security teams should assess exposure and prioritize verification of affected systems, especially those with unprivileged userspace daemons interacting with ublk devices.
Why it matters
CVE-2026-89793 is a vulnerability in the Linux kernel's ublk subsystem that allows an unprivileged userspace daemon to corrupt kernel-written ABI data. Linux kernel developers and administrators should assess exposure and prioritize verification of affected systems.
- Unprivileged daemon can corrupt kernel-written ABI data in the per-queue command buffer.
- Potential data corruption or unauthorized modifications to kernel data.
- Verification of affected systems and patch application are required to prevent exploitation.
- Monitoring for potential data corruption or unauthorized modifications to kernel data is necessary.
Technical summary
The ublk_ch_mmap() function in the Linux kernel fails to clear VM_MAYWRITE on read-only ublk char device mappings. This allows an unprivileged userspace daemon to mmap the per-queue command buffer with PROT_READ and then upgrade it to PROT_WRITE via mprotect(). The command buffer holds struct ublksrv_io_desc entries that are kernel-written ABI; a writable mapping lets the daemon corrupt fields such as addr, op_flags, nr_sectors, and start_sector.
Defensive priority
Linux kernel developers and administrators should assess exposure and prioritize verification of affected systems, especially those with unprivileged userspace daemons interacting with ublk devices.
Recommended defensive actions
- Review and apply the provided Linux kernel patches to address the vulnerability.
- Assess exposure of Linux kernel deployments, especially those with unprivileged userspace daemons interacting with ublk devices.
- Verify that affected systems are upgraded to a patched version of the Linux kernel.
- Monitor for potential data corruption or unauthorized modifications to kernel data.
- Perform a thorough review of system logs to detect any potential exploitation attempts.
- Implement additional monitoring and logging to track access to affected systems.
- Conduct a thorough asset inventory to identify all systems that may be affected by this vulnerability.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected components. The Linux kernel source code references are provided, but specific affected versions are not explicitly mentioned.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-89793 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-89793
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-89793 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89793
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5befd06a72216869b607cf7724a4f16c6a2d3999
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6e2b571b0a54755b06e092501913e1dfefe75d6c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/be41733c24be58e2a1ef718c80fafdfb98a40d5e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e373c1acdbcf88cec533ece9f589020adaed0a78
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/fa5e1bc673ca59722608af67b27e65dba0c97926
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.