Description
In the Linux kernel, the following vulnerability has been resolved:

debugfs: Fix lockdown check for mmap_prepare

Commit 651fdda8406d ("relay: update relay to use mmap_prepare")
changed the `mmap` file operation to `mmap_prepare` for relayfs, but
the lockdown check in debugfs was not updated accordingly.

This prevents debugfs from being locked down when the kernel is in
integrity mode if a file uses `mmap_prepare` but not `mmap`.

Since the conversion to `mmap_prepare` across the kernel is not yet
complete, update the lockdown check to look for both `mmap` and
`mmap_prepare` to ensure comprehensive coverage.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privileged Debugfs Access Under Lockdown
Action: Patch
AI Analysis

Impact

The vulnerability originates in the kernel’s debugfs handling. When the system is operating in integrity lockdown mode, kernel data is protected by blocking certain file operations. The lockdown check was expanded to include the old mmap operation but did not also consider mmap_prepare. Because some files use allowing an attacker to read or manipulate debugfs data that should be inaccessible when lockdown is active.

Affected Systems

The flaw affects Linux kernels that have the lockdown feature compiled in and that mount a debugfs file system. No explicit vendor or version list is supplied in the advisory; therefore, any kernel build that has not yet incorporated the patch to apply the mmap_prepare check remains vulnerable. The damage is limited to systems running a debugfs mount point under lockdown. If a custom build omits the patch, that build is also affected.

Risk and Exploitability

The CVSS score of 4.4 reflects a moderate severity level. The EPSS score of less than 1% indicates a very low probability that this vulnerability will be actively exploited. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is local, requiring the attacker to have the ability to invoke mmap_prepare against a debugfs file; remote exploitation would be. If exploited successfully, an attacker can read or modify privileged debug information that should be hidden by lockdown mode, compromising kernel integrity and potentially enabling further attacks.

Generated by OpenCVE AI on September 15, 2026 at 19:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that adds the mmap_prepare check to the lockdown code, ensuring the updated lockdown logic runs for both mmap and mmap_prepare.
  • Rebuild or update the kernel to a version that includes the patch if you maintain a custom build.
  • If an immediate patch is not feasible, consider remounting or unmounting the debugfs file system as read‑only to reduce exposure to exploitation.

Generated by OpenCVE AI on September 15, 2026 at 19:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-414
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Sat, 12 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: debugfs: Fix lockdown check for mmap_prepare Commit 651fdda8406d ("relay: update relay to use mmap_prepare") changed the `mmap` file operation to `mmap_prepare` for relayfs, but the lockdown check in debugfs was not updated accordingly. This prevents debugfs from being locked down when the kernel is in integrity mode if a file uses `mmap_prepare` but not `mmap`. Since the conversion to `mmap_prepare` across the kernel is not yet complete, update the lockdown check to look for both `mmap` and `mmap_prepare` to ensure comprehensive coverage.
Title debugfs: Fix lockdown check for mmap_prepare
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:46:50.758Z

Reserved: 2026-09-11T19:38:34.762Z

Link: CVE-2026-89745

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:05.260

Modified: 2026-09-11T20:20:05.260

Link: CVE-2026-89745

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:50Z

Links: CVE-2026-89745 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses