CVE-2026-89793

Source
https://cve.org/CVERecord?id=CVE-2026-89793
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89793.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89793
Downstream
Related
Published
2026-09-16T09:54:33Z
Modified
2026-10-06T02:47:52Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ublk: clear VM_MAYWRITE on read-only ublk char device mmap
Details

In the Linux kernel, the following vulnerability has been resolved:

ublk: clear VM_MAYWRITE on read-only ublk char device mmap

ublk_ch_mmap() rejects mmap requests with VM_WRITE set, but never clears VM_MAYWRITE on the resulting read-only mapping. This allows a userspace daemon to mmap the per-queue command buffer PROT_READ, then upgrade it to PROT_WRITE via mprotect(), since VM_MAYWRITE was never cleared.

The command buffer holds struct ublksrv_io_desc entries that are kernel-written ABI; a writable mapping lets an unprivileged daemon process corrupt fields such as addr, op_flags, nr_sectors, and start_sector.

Same bug class as the drm/panthor and drm/vc4 VM_MAYWRITE fixes, and the 2026-08-13 ptp/vmclock fix (a5edadbae57e).

Verified via mprotect() PoC: before the fix, a PROT_READ mapping can be upgraded to PROT_READ|PROT_WRITE and a write into the command buffer corrupts io_desc fields (confirmed under KASAN). After the fix, mprotect() returns -EACCES.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89793.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
71f28f3136aff5890cd56de78abc673f8393cad9
Fixed
be41733c24be58e2a1ef718c80fafdfb98a40d5e
Fixed
5befd06a72216869b607cf7724a4f16c6a2d3999
Fixed
e373c1acdbcf88cec533ece9f589020adaed0a78
Fixed
fa5e1bc673ca59722608af67b27e65dba0c97926
Fixed
6e2b571b0a54755b06e092501913e1dfefe75d6c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89793.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89793.json"