Description
In the Linux kernel, the following vulnerability has been resolved:

ecryptfs: release message context on send failure

ecryptfs_send_message_locked() moves a message context from the free
list to the allocated list before sending the request to the userspace
daemon.

If ecryptfs_send_miscdev() fails, the context is left on the
allocated list and cannot be reused. Move it back to the free list on
failure and clear the caller's pointer.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

The ecryptfs subsystem in the Linux kernel fails to release a message context when a send to the userspace daemon fails. The context remains allocated on the ecryptfs allocated list, preventing reuse and eventually exhausting the available context pool. This resource leak can cause the ecryptfs filesystem to become unusable, constituting a denial‑of‑service condition. The weakness is recognized as a resource leak (CWE‑772) and does not directly threaten confidentiality or integrity.

Affected Systems

Any Linux kernel build that includes the ecryptfs module is affected. The vulnerability is present in the kernel source starting with the commit that introduced the bug and remains until patched. All distributions that ship a kernel with ecryptfs compiled (for example most mainstream distributions) fall under this scope, regardless of whether the module is enabled at boot or loaded dynamically.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.8, classifying it as high severity. The EPSS score of < 1% indicates a very low likelihood of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Exploitation would likely require a local or privileged user able to repeatedly trigger ecryptfs send failures, such as by interacting with the userspace daemon or manipulating file operations that invoke ecryptfs_send_miscdev. The impact is purely availability; no confidentiality or integrity impact is afforded. Given the high severity and low exploitation probability, system administrators should treat this as a high priority update.

Generated by OpenCVE AI on September 15, 2026 at 21:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that incorporates the ecryptfs_send_message_locked fix, such as the latest stable release from your distribution’s kernel repository.
  • If an update is not possible, blacklist the ecryptfs module to prevent it from loading by adding an entry like “blacklist ecryptfs” to /etc/modprobe.d/ and unload any currently loaded instance with modprobe -r ecryptfs.
  • Monitor system logs for repeated ecryptfs send failures (look for messages containing \"ecryptfs send\") and investigate any incidents promptly.

Generated by OpenCVE AI on September 15, 2026 at 21:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ecryptfs: release message context on send failure ecryptfs_send_message_locked() moves a message context from the free list to the allocated list before sending the request to the userspace daemon. If ecryptfs_send_miscdev() fails, the context is left on the allocated list and cannot be reused. Move it back to the free list on failure and clear the caller's pointer.
Title ecryptfs: release message context on send failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:25.672Z

Reserved: 2026-09-11T19:38:34.733Z

Link: CVE-2026-89605

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:45.487

Modified: 2026-09-14T13:19:14.590

Link: CVE-2026-89605

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:08Z

Links: CVE-2026-89605 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime