PatchSiren cyber security CVE debrief
CVE-2026-89996 Linux CVE debrief
A vulnerability in the Linux kernel's dma-buf subsystem can cause a file descriptor leak when the dma_heap_ioctl() function fails. This occurs because the function installs an fd into the caller's fd table before copying the result back to userspace, and if the copy_to_user() fails, the fd is not closed. The issue can be triggered by passing a struct dma_heap_allocation_data that lives in a page whose protection is flipped to PROT_READ between copy_from_user() and copy_to_user().
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-10-03
Who should care
Linux kernel developers and maintainers, as well as users of Linux-based systems, should be aware of this vulnerability and take steps to mitigate it. Affected operator teams, platform administrators, vulnerability management teams, and security teams should review and apply patches, monitor for potential exploitation attempts, and verify affected systems.
Why it matters
The Linux kernel dma-buf subsystem vulnerability can cause a file descriptor leak, potentially leading to resource exhaustion and denial of service. Linux kernel developers and maintainers should review and apply patches to fix the issue.
- Potential file descriptor leak, requiring verification of affected systems
- Possible denial of service due to resource exhaustion, requiring monitoring and patching
Technical summary
The dma_heap_ioctl_allocate() function in the Linux kernel's dma-buf subsystem allocates a dma-buf and installs an fd into the caller's fd table before copying the result back to userspace. If the copy_to_user() fails, the fd is not closed, causing a file descriptor leak. The issue can be triggered by passing a struct dma_heap_allocation_data that lives in a page whose protection is flipped to PROT_READ between copy_from_user() and copy_to_user().
Defensive priority
Medium
Recommended defensive actions
- Review and apply the Linux kernel patches that fix the dma-buf vulnerability
- Monitor systems for potential exploitation attempts
- Verify that affected systems are updated with the patched kernel
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, including its description and references to the Linux kernel patches that fix the issue. Linux kernel developers and maintainers should verify affected systems, review and apply patches, and monitor for potential exploitation attempts. The issue can be triggered by passing a struct dma_heap_allocation_data that lives in a page whose protection is flipped to PROT_READ between copy_from_user() and copy_to_user().
Sources and references
Verified primary and authoritative sources
-
CVE-2026-89996 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-89996
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-89996 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89996
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0d4a5d218055db29b50cc07d3d73d27007c2a391
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1bf6083a41f810d760c4dcd1b80c5194a92575aa
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/30d0aff2c65a277135cfd8ea28fa1ee75e0ea4e0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/69d57dbadb27ffd5eef34fd184bab145500cdabc
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.