# CVE-2026-89497

## Summary

- **CVE ID:** CVE-2026-89497
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

orangefs: skip leading spaces before parsing client debug masks

orangefs_prepare_cdm_array() sizes each client debug keyword buffer
with strcspn(cds_head, " "), but then parses the keyword with %s. The
%s conversion skips leading whitespace, while strcspn() does not.

If a client debug entry starts with a space, the allocation can be sized
for an empty keyword while sscanf() copies the following non-empty token.
This can write past the end of the allocated keyword buffer.

Skip leading spaces before computing the keyword length so the allocation
matches the string parsed by sscanf().

## Affected Products

- Linux — Linux (f7be4ee07fb72a516563bc2870ef41fa589a964a)
- Linux — Linux (4.6)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/15d79c806231e62a7b746d3b42626810004e1b27)
- [CNA](https://git.kernel.org/stable/c/116d14f29a0524853c9316f32a2ac06cff5d4bf6)
- [CNA](https://git.kernel.org/stable/c/1774c5b3713add32fe15ab0d3db4b73355f94e35)
- [CNA](https://git.kernel.org/stable/c/d410cd5303ec59c7cf23dd61423752ce8e9ecb59)
- [CNA](https://git.kernel.org/stable/c/173bfd69696815bcf1c052f61cb69c26cca4e443)
- [CNA](https://git.kernel.org/stable/c/995f4d05589f87452a56672270af28918c8939c3)
- [CNA](https://git.kernel.org/stable/c/0ef38d53bca5ea1375fea0d3d11e9727df064b85)
- [CNA](https://git.kernel.org/stable/c/ce748ae1181d0daf5dd0d2d906d5c1cc328c153b)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._