# CVE-2026-89605

## Summary

- **CVE ID:** CVE-2026-89605
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ecryptfs: release message context on send failure

ecryptfs_send_message_locked() moves a message context from the free
list to the allocated list before sending the request to the userspace
daemon.

If ecryptfs_send_miscdev() fails, the context is left on the
allocated list and cannot be reused. Move it back to the free list on
failure and clear the caller's pointer.

## Affected Products

- Linux — Linux (f66e883eb6186bc43a79581b67aff7d1a69d0ff1)
- Linux — Linux (2.6.26)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/47ce611cb13f0eefa550d5434c1afcd4217bfc3e)
- [CNA](https://git.kernel.org/stable/c/9319706316a8e79f374627554386d575a84b637f)
- [CNA](https://git.kernel.org/stable/c/654b7e79443f5ea90849f5c1cf70c0d94bd5b10e)
- [CNA](https://git.kernel.org/stable/c/219644a3ad5518217b2d62cad6d2c36a2308c949)
- [CNA](https://git.kernel.org/stable/c/177e0c32fec3602bb3b64139bb8bb610cd6722c7)
- [CNA](https://git.kernel.org/stable/c/743e7aeb9575c0838d8996d40d81a6b8fa5cd060)
- [CNA](https://git.kernel.org/stable/c/590fc6140e29c54d2f7839eb9df78d106ee1905e)
- [CNA](https://git.kernel.org/stable/c/30845ed227475a11a49ccce047837d016b7e0f49)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 6.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._