Description
In the Linux kernel, the following vulnerability has been resolved:

audit: avoid dropping live tree ref on fsnotify rule autoremove

audit_del_rule() is used for both netlink deletion templates and internal
fsnotify autoremove. The former passes a parsed template which owns a
temporary tree reference; the latter passes the installed entry itself.

The unconditional audit_put_tree() at the end of audit_del_rule() assumes
the template case. For mixed AUDIT_DIR plus AUDIT_EXE rules, an fsnotify
autoremove event therefore drops the installed rule's live tree reference.
Repeating this across rules sharing the same tree can free the tree while
another rule still references it, and a later autoremove dereferences the
freed pathname while comparing rules.

Move the temporary-tree put to audit_rule_change(), the caller that owns
deletion templates. Keep it in the AUDIT_DEL_RULE cleanup so both
successful deletion and -ENOENT still release the parser-owned tree.

[PM: dropped unnecessary comment for line length reasons]
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free in Audit Subsystem
Action: Patch Kernel
AI Analysis

Impact

In the Linux kernel’s audit subsystem, audit_del_rule() drops a temporary tree reference during filesystem notification autoremove. The unconditional audit_put_tree() call assumes a template case, but for rules that mix AUDIT_DIR and AUDIT_EXE types, the autoremove removes the live tree reference. Repeated autoremove events can free a tree that other audit rules still reference that can corrupt memory and potentially crash the kernel. This weakness is classified as CWE‑825.

Affected Systems

All Linux kernel packages that include the unpatched audit framework code before the patch backports or patches beyond the commit itself are affected.

Risk and Exploitability

The CVSS score of 9.8 classifies this flaw as critical. The EPSS score of under 1% indicates a low but non‑zero probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is a local or privileged user who can add or remove audit rules. Repeatedly deleting mixed AUDIT_DIR and AUDIT_EXE rules can trigger the use‑after‑free, potentially causing a kernel crash or memory corruption.

Generated by OpenCVE AI on September 15, 2026 at 21:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the audit_del_rule patch from the upstream Linux repository.
  • Restrict audit rule modification to privileged administrators only and enforce role‑based access control for audit configuration changes.
  • Reconfigure audit to avoid mixing AUDIT_DIR and AUDIT_EXE rules in the same rule set, or remove such rule sets if they are not required.

Generated by OpenCVE AI on September 15, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Linux linux
Vendors & Products Linux linux

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: audit: avoid dropping live tree ref on fsnotify rule autoremove audit_del_rule() is used for both netlink deletion templates and internal fsnotify autoremove. The former passes a parsed template which owns a temporary tree reference; the latter passes the installed entry itself. The unconditional audit_put_tree() at the end of audit_del_rule() assumes the template case. For mixed AUDIT_DIR plus AUDIT_EXE rules, an fsnotify autoremove event therefore drops the installed rule's live tree reference. Repeating this across rules sharing the same tree can free the tree while another rule still references it, and a later autoremove dereferences the freed pathname while comparing rules. Move the temporary-tree put to audit_rule_change(), the caller that owns deletion templates. Keep it in the AUDIT_DEL_RULE cleanup so both successful deletion and -ENOENT still release the parser-owned tree. [PM: dropped unnecessary comment for line length reasons]
Title audit: avoid dropping live tree ref on fsnotify rule autoremove
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:43.871Z

Reserved: 2026-09-11T19:38:34.741Z

Link: CVE-2026-89643

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:50.090

Modified: 2026-09-14T13:19:17.080

Link: CVE-2026-89643

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:35Z

Links: CVE-2026-89643 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference