Vulnary
← back to the feed
Critical· 9.8official fix available

CVE-2026-89643

This is a Linux kernel audit bug that can occur when filesystem notification rules are removed automatically, particularly when directory and executable rules share an audit tree. The kernel may free pathname data still referenced by another rule, so a later rule comparison can try to use memory that has already been freed.

publishedSep 11, 2026
last modifiedSep 13, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
10th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 13, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Linux kernel users may be affected, but the sources do not list specific affected products or versions.

02

Real-world impact

The issue may make kernel audit operations unstable by causing them to access memory after it has been freed.

03

Why this severity

The vulnerability has a critical CVSS score of 9.8. Its vector indicates exploitation over a network, with low complexity, no required privileges, no user interaction, and potential high impact on confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade the Linux kernel to a release that contains the audit rule reference-handling fix for CVE-2026-89643.

The Linux kernel source note states that the vulnerability has been resolved, but it does not provide an affected version, patch number, or vendor advisory.

05

Timeline

  1. Sep 11, 2026 · 2d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Sep 13, 2026 · 7h ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →