ring-buffer: Fix subbuf resize race with ring buffer readers
Summary
| CVE | CVE-2026-89771 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:20:08 UTC |
| Updated | 2026-09-11 20:20:08 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
ring-buffer: Fix subbuf resize race with ring buffer readers
trace_buffer subbuf_size is read lockless in ring_buffer_read_page() and
ring_buffer_read_start(), while it can simultaneously be resized with
ring_buffer_subbuf_order_set().
Instead of trace_buffer::subbuf_size, use bpage::order in
ring_buffer_read_start() and ring_buffer_read_page().
In ring_buffer_read_start(), even with resize_disabled, there is still a
possibility of a race with a buffer modification. Hold the trace_buffer
mutex to synchronise with any pending ring buffer order modification.
trace_buffer::subbuf_size is now actually useless, remove it. Also,
create accessors rb_subbuf_capacity() and rb_page_capacity() which
return the actual size available for storing events, while
rb_subbuf_size() returns the actual subbuf page-size. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected f9b94daa542a8d2532f0930f01cd9aec2d19621b 6d666f0b8b36c0765cf19fbe6de5a7ba5a73aad9 git |
Not specified |
| CNA |
Linux |
Linux |
affected f9b94daa542a8d2532f0930f01cd9aec2d19621b 50f4a793c4ff24826efb0ac700989a5063cc53df git |
Not specified |
| CNA |
Linux |
Linux |
affected f9b94daa542a8d2532f0930f01cd9aec2d19621b 0c7c517827a453128a8f58bfd849546a29813b27 git |
Not specified |
| CNA |
Linux |
Linux |
affected f9b94daa542a8d2532f0930f01cd9aec2d19621b 8a5f63637890f03177146efddaba5ec7a1b4d61f git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.8 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.8 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/6d666f0b8b36c0765cf19fbe6de5a7ba5a73aad9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/50f4a793c4ff24826efb0ac700989a5063cc53df |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8a5f63637890f03177146efddaba5ec7a1b4d61f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0c7c517827a453128a8f58bfd849546a29813b27 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.