PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-89996 Linux CVE debrief

A vulnerability in the Linux kernel's dma-buf subsystem can cause a file descriptor leak when the dma_heap_ioctl() function fails. This occurs because the function installs an fd into the caller's fd table before copying the result back to userspace, and if the copy_to_user() fails, the fd is not closed. The issue can be triggered by passing a struct dma_heap_allocation_data that lives in a page whose protection is flipped to PROT_READ between copy_from_user() and copy_to_user().

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-10-03
Advisory published
2026-09-16
Advisory updated
2026-10-03

Who should care

Linux kernel developers and maintainers, as well as users of Linux-based systems, should be aware of this vulnerability and take steps to mitigate it. Affected operator teams, platform administrators, vulnerability management teams, and security teams should review and apply patches, monitor for potential exploitation attempts, and verify affected systems.

Why it matters

The Linux kernel dma-buf subsystem vulnerability can cause a file descriptor leak, potentially leading to resource exhaustion and denial of service. Linux kernel developers and maintainers should review and apply patches to fix the issue.

  • Potential file descriptor leak, requiring verification of affected systems
  • Possible denial of service due to resource exhaustion, requiring monitoring and patching

Technical summary

The dma_heap_ioctl_allocate() function in the Linux kernel's dma-buf subsystem allocates a dma-buf and installs an fd into the caller's fd table before copying the result back to userspace. If the copy_to_user() fails, the fd is not closed, causing a file descriptor leak. The issue can be triggered by passing a struct dma_heap_allocation_data that lives in a page whose protection is flipped to PROT_READ between copy_from_user() and copy_to_user().

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the Linux kernel patches that fix the dma-buf vulnerability
  • Monitor systems for potential exploitation attempts
  • Verify that affected systems are updated with the patched kernel
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, including its description and references to the Linux kernel patches that fix the issue. Linux kernel developers and maintainers should verify affected systems, review and apply patches, and monitor for potential exploitation attempts. The issue can be triggered by passing a struct dma_heap_allocation_data that lives in a page whose protection is flipped to PROT_READ between copy_from_user() and copy_to_user().

Sources and references

Verified primary and authoritative sources

  • CVE-2026-89996 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-89996

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-89996 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89996

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0d4a5d218055db29b50cc07d3d73d27007c2a391

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1bf6083a41f810d760c4dcd1b80c5194a92575aa

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/30d0aff2c65a277135cfd8ea28fa1ee75e0ea4e0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/69d57dbadb27ffd5eef34fd184bab145500cdabc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.