# CVE-2026-89602

## Summary

- **CVE ID:** CVE-2026-89602
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 13, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

erofs: skip sufficiently large global buffers when resizing

z_erofs_gbuf_nrpages is advanced only after every global buffer has been
grown. If a resize fails after some buffers were enlarged, a retry
revisits those enlarged buffers.

Retrying the same size then returns -ENOMEM because alloc_pages_bulk()
has no pages to add and the unchanged return value is treated as a
failure. Retrying an intermediate size allocates a temporary pointer
array smaller than gbuf->nrpages and copies more existing pointers than
the array can hold.

Skip buffers that already satisfy the request. Once all remaining
buffers have caught up, advancing z_erofs_gbuf_nrpages again describes
the guaranteed minimum size across the pool.

## Affected Products

- Linux — Linux (d6db47e571dcaecaeaafa8840d00ae849ae3907b)
- Linux — Linux (6.10)
- Linux — Linux (0)
- Linux — Linux (6.18.51)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/7267557ce98ccd07faaf3bc86382448950cc4ff6)
- [CNA](https://git.kernel.org/stable/c/7f4a89d4f0d6acaf4b756c31de48f2109a257b70)
- [CNA](https://git.kernel.org/stable/c/a7d097cf01301c5da37927c8f26123d006f0fd8a)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._