Description
In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Stop remote reader update when page swap fails

The remote swap_reader_page callback can return -EBUSY when the writer
moves the head before the remote catches it, particularly during an event
storm on a small buffer. __rb_get_reader_page_from_remote() currently
warns about that failure but continues with the unchanged reader ID and
rearranges the local page list as though the swap succeeded.

Handle the callback failure as a recoverable error. Report it with
pr_warn_ratelimited() and return NULL. Callers already handle a NULL reader
page as a failed attempt. This avoids splicing the same page as both the
previous and new reader without flooding the log under contention.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Apply patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel when the remote swap_reader_page callback can return an error such as -EBUSY, but the kernel code still continues to use the stale reader ID and rearranges the ring buffer page list as though the swap succeeded. This incorrect handling can leave the same memory page marked as both the previous and new reader, potentially corrupting kernel memory. The flaw is a failure to properly handle an error return, identified by CWE-390.

Affected Systems

All Linux kernel releases that do not include the commit referenced in the advisory are affected. The vendor list indicates the entire Linux kernel product line, and no specific version ranges are provided, so any distribution shipping an unpatched kernel is at risk.

Risk and Exploitability

The CVSS score of 7.8 signals a high severity vulnerability that can lead to data integrity loss. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation in the wild, and the issue is not listed in CISA's KEV catalog. Although no public exploits are known, the likely attack vector involves a local or privileged process that can trigger event storms on small ring buffers, thereby exercising the faulty path.

Generated by OpenCVE AI on September 21, 2026 at 01:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the kernel patch that implements the commit referenced in the advisory, or upgrade to a kernel version that includes the change.
  • If a kernel upgrade is currently infeasible, configure monitoring to detect the pr_warn_ratelimited warning messages emitted when a swap_reader_page failure occurs, and reduce load on remote ring‑buffer interfaces when such warnings appear.
  • Ensure that any custom code that calls __rb_get_reader_page_from_remote checks for a NULL return and treats it as a failed swap rather than proceeding with the old reader state.

Generated by OpenCVE AI on September 21, 2026 at 01:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sat, 12 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-390
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Stop remote reader update when page swap fails The remote swap_reader_page callback can return -EBUSY when the writer moves the head before the remote catches it, particularly during an event storm on a small buffer. __rb_get_reader_page_from_remote() currently warns about that failure but continues with the unchanged reader ID and rearranges the local page list as though the swap succeeded. Handle the callback failure as a recoverable error. Report it with pr_warn_ratelimited() and return NULL. Callers already handle a NULL reader page as a failed attempt. This avoids splicing the same page as both the previous and new reader without flooding the log under contention.
Title ring-buffer: Stop remote reader update when page swap fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:30:06.162Z

Reserved: 2026-09-11T19:38:34.715Z

Link: CVE-2026-89499

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:32.063

Modified: 2026-09-13T07:17:13.100

Link: CVE-2026-89499

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:48Z

Links: CVE-2026-89499 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:15:03Z

Weaknesses
  • CWE-390

    Detection of Error Condition Without Action