# CVE-2026-89502

## Summary

- **CVE ID:** CVE-2026-89502
- **Severity:** UNKNOWN
- **CVSS Score:** 1.51
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Free cpu_buffer::free_page with subbuf_order

When sub-buffers use an order greater than 0, cpu_buffer->free_page is
allocated with subbuf_order. Use the correct order for
cpu_buffer->free_page.

## Affected Products

- Linux — Linux (f9b94daa542a8d2532f0930f01cd9aec2d19621b)
- Linux — Linux (6.8)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/77275ccea06eaf297e8e6ac3fc830cb72086379a)
- [CNA](https://git.kernel.org/stable/c/8c1ecdcdea738efe0494af908f12c0ae3a97fffa)
- [CNA](https://git.kernel.org/stable/c/81063bbb16c4fcf0136c9117d5e49d3621dd6a1e)
- [CNA](https://git.kernel.org/stable/c/234b1a72e9706fe20c08c96f4374ec8e83b934cb)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 10.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._