Description
In the Linux kernel, the following vulnerability has been resolved:

ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()

dentry_path() returns ERR_PTR(-ENAMETOOLONG) when the path exceeds the
buffer. validate_hash_algo() passes the result straight to
integrity_audit_msg() without checking. ERR_PTR is not NULL, so
integrity_audit_message() sees a valid pointer and calls strlen() on
it, which faults:

BUG: unable to handle page fault for address: ffffffffffffffdc
RIP: 0010:strlen+0x30/0xa0
Call Trace:
audit_log_untrustedstring+0x19/0x30
integrity_audit_message+0x366/0x4f0
ima_inode_setxattr+0x512/0x5f0

Check for IS_ERR() and use NULL instead, which makes the audit message
skip the name= field instead of crashing.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash leading to Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel when the integrity audit subsystem processes a pathname that exceeds the buffer limit. The helper function dentry_path() returns an error encoded as a pointer (ERR_PTR(-ENAMETOOLONG)) which the validate_hash_algo() routine passes straight to integrity_audit_msg() without checking for errors. The audit message routine then treats the error pointer as a valid string and calls strlen() on it, causing a page fault and the kernel to panic. The crash precludes the system from maintaining normal operation and can be triggered by providing a specially crafted file name during inode attribute set operations, leading to a denial‑of‑service condition. Affected systems This flaw affects all Linux kernel builds that include the IMA integrity audit feature, specifically any kernel that has not applied the patch referenced in the supplied Git revisions. The vulnerability is present in the Linux kernel source tree and is active in the environment described. Vendors that ship Linux kernel binaries without the patch are impacted, regardless of the distribution or kernel version. Risk and exploitability The CVSS details are not explicitly reported, but the EPSS score is listed as less than 1%, indicating a very low to negligible exploitation probability at the time of analysis. However, the impact of a successful exploit is severe, causing a kernel panic and reboot. The risk is therefore high in environments where the audit feature is enabled and where an attacker can influence the creation or modification of files with excessively long names. The vulnerability is not currently listed in the CISA KEV catalog, so there is no confirmed widespread exploitation yet, but the potential for a local privilege escalation or data corruption remains.

Affected Systems

Linux kernel installations that include the Inode Mount Audit (IMA) subsystem, specifically any build prior to the patch commits referenced in the provided Git URLs. All vendors shipping standard Linux kernels without this patch are affected.

Risk and Exploitability

The flaw carries a high impact if triggered, but the EPSS score of <1% suggests that exploitation is unlikely to occur in the wild at this time. The vulnerability is not in the CISA KEV list, so no public exploits are documented. The attack would require local interaction or low‑privileged code that can perform an inode setxattr operation with a path exceeding the buffer.

Generated by OpenCVE AI on September 18, 2026 at 03:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the fix for the IMA integrity audit error pointer check.
  • Deploy the official patch that adds an IS_ERR() validation before calling strlen on the path returned by dentry_path().
  • If a kernel upgrade is not immediately possible, disable integrity auditing or the IMA subsystem to prevent kernel crashes until a patch can be applied.

Generated by OpenCVE AI on September 18, 2026 at 03:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ima: Check for ERR_PTR from dentry_path() in validate_hash_algo() dentry_path() returns ERR_PTR(-ENAMETOOLONG) when the path exceeds the buffer. validate_hash_algo() passes the result straight to integrity_audit_msg() without checking. ERR_PTR is not NULL, so integrity_audit_message() sees a valid pointer and calls strlen() on it, which faults: BUG: unable to handle page fault for address: ffffffffffffffdc RIP: 0010:strlen+0x30/0xa0 Call Trace: audit_log_untrustedstring+0x19/0x30 integrity_audit_message+0x366/0x4f0 ima_inode_setxattr+0x512/0x5f0 Check for IS_ERR() and use NULL instead, which makes the audit message skip the name= field instead of crashing.
Title ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:33:03.703Z

Reserved: 2026-09-11T19:38:34.780Z

Link: CVE-2026-89989

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:10.010

Modified: 2026-09-16T11:17:10.010

Link: CVE-2026-89989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:15:13Z

Weaknesses