Description
In the Linux kernel, the following vulnerability has been resolved:

orangefs: fix double-free of trailer_buf on readdir copy failure

On a readdir downcall, orangefs_devreq_write_iter() frees
op->downcall.trailer_buf with vfree() when copy_from_iter_full() fails,
but does not clear the pointer before goto Efault. The waiter in
do_readdir() is then woken with a negative status and frees the same
pointer again on its r < 0 path, causing a deterministic double-free.
A client holding /dev/pvfs2-req triggers it by sending a readdir
downcall whose declared trailer_size exceeds the bytes it supplies.

Clear the pointer after freeing so the readdir-side vfree() becomes a
no-op.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel double‑free leading to memory corruption
Action: Apply kernel update
AI Analysis

Impact

In the Linux kernel’s orangefs filesystem driver, a readdir operation can trigger a deterministic double‑free of the trailer buffer when copy_from_iter_full() fails. The first free occurs in orangefs_devreq_write_iter(), but the pointer is not cleared before falling into error handling; later, do_readdir() frees the same buffer again. This double‑free corrupts the kernel heap, which may allow an attacker to execute arbitrary code or crash the system, depending on how the heap is subsequently used.

Affected Systems

All Linux kernel releases that include the orangefs module are affected. The vulnerability is triggered by a local user with access to the character device it does not require elevated privileges beyond those needed to perform the readdir operation.

Risk and Exploitability

The CVSS score of 4.1 and an EP probability of exploitation in the wild. The flaw is identified as CWE‑763 (Improper Memory Management). A malformed readdir downcall that causes copy_from_iter_full() to fail will trigger a deterministic double‑free leading to memory corruption that could result in denial of service or code execution if additional conditions are met. The vulnerability is not listed in the CISA KEV catalog, implying no known exploitation has been observed.

Generated by OpenCVE AI on September 21, 2026 at 01:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the orangefs patch.
  • Unload or disable the orangefs module if upgrading is not immediately possible.
  • Restrict access to /dev/pvfs2-req so only trusted users can perform readdir operations.

Generated by OpenCVE AI on September 21, 2026 at 01:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-763
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: orangefs: fix double-free of trailer_buf on readdir copy failure On a readdir downcall, orangefs_devreq_write_iter() frees op->downcall.trailer_buf with vfree() when copy_from_iter_full() fails, but does not clear the pointer before goto Efault. The waiter in do_readdir() is then woken with a negative status and frees the same pointer again on its r < 0 path, causing a deterministic double-free. A client holding /dev/pvfs2-req triggers it by sending a readdir downcall whose declared trailer_size exceeds the bytes it supplies. Clear the pointer after freeing so the readdir-side vfree() becomes a no-op.
Title orangefs: fix double-free of trailer_buf on readdir copy failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:33.199Z

Reserved: 2026-09-11T19:38:34.714Z

Link: CVE-2026-89498

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:31.940

Modified: 2026-09-14T13:19:07.087

Link: CVE-2026-89498

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:48Z

Links: CVE-2026-89498 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:15:03Z

Weaknesses
  • CWE-763

    Release of Invalid Pointer or Reference