# CVE-2026-89500

## Summary

- **CVE ID:** CVE-2026-89500
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 13, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page

Discarding a cached reader page after a concurrent ring buffer resize
uses the new global subbuf_order for the free_pages() call. This
mismatched order may crashes the kernel or leaks memory because the cached
page was allocated under the old size.

Save the actual free_page order alongside the page address to ensure we
always refer to the correct value and do not rely on the potentially
stalled cpu_buffer->subbuf_order value. The simplest is to make
free_page a buffer_data_read_page which already covers exactly what we
need: a page address and a page order.

## Affected Products

- Linux — Linux (8e7b58c27b3c567316a51079b375b846f9223bba)
- Linux — Linux (6.8)
- Linux — Linux (0)
- Linux — Linux (6.18.51)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/a1dabe68fb53730bc0be60c5dbfd3f4c560084e7)
- [CNA](https://git.kernel.org/stable/c/d787d509bdf6c88c85e095247daf7456cb7fb772)
- [CNA](https://git.kernel.org/stable/c/7a1fb95de5404134f8758c1295ce88986bdf117c)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._