Description
In the Linux kernel, the following vulnerability has been resolved:

dm: fix resume-vs-remove race

If the user issues the resume ioctl and the remove ioctl at the same
time, it may be possible that the device is resumed after it is suspended
in __dm_destroy. The result is that the table is destroyed without
calling the postsuspend method.

Dm targets expect that they may be removed only after the postsuspend
method method was called. If we break this expectation, it can cause
misbehavior in various targets. For example - in the dm-integrity target,
the reboot notifier is not unregistered, leading to use-after-free.

Fix this bug by refusing to resume if the device is being destroyed.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to kernel crash or privilege escalation
Action: Patch
AI Analysis

Impact

In the Linux kernel, a race condition exists between the resume and remove ioctl operations for device mapper devices. If a resume request is handled concurrently with a remove request, the device may be resumed after the kernel starts destroying its context. This results in the dm_table being freed without calling the required postsuspend callback. Device mapper targets that expect that callback can misbehave, such as the dm-integrity target leaving a reboot notifier registered, which can cause a use‑after‑free when the system reboots. The flaw is a classic use‑after‑free in kernel memory and could allow a privileged attacker to crash the system or execute code with kernel privileges.

Affected Systems

The affected product is the Linux kernel. All kernel releases that omit the commit that introduces the dm: fix resume‑vs‑remove race patch are vulnerable. Because the vulnerability is triggered by the interaction of two privileged ioctl calls, any system running an unpatched kernel is at risk where a local user with permission to issue device mapper ioctl operations could trigger the race.

Risk and Exploitability

The CVSS score of 7.8 places the flaw in the high severity range. The EPSS score indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation is best‑effort and requires a local attacker who can perform the two ioctl calls concurrently, likely at privileged level. Once the race is exploited, the use‑after‑free can lead to a kernel crash or privilege escalation, thereby raising the impact if the attacker gains a foothold.

Generated by OpenCVE AI on September 18, 2026 at 08:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the dm: fix resume‑vs‑remove race patch
  • If an immediate kernel upgrade is not possible, serialize the use of the resume and remove ioctls so that they cannot be issued concurrently
  • Disable the affected device mapper targets, such as dm-integrity, until the kernel patch is applied

Generated by OpenCVE AI on September 18, 2026 at 08:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm: fix resume-vs-remove race If the user issues the resume ioctl and the remove ioctl at the same time, it may be possible that the device is resumed after it is suspended in __dm_destroy. The result is that the table is destroyed without calling the postsuspend method. Dm targets expect that they may be removed only after the postsuspend method method was called. If we break this expectation, it can cause misbehavior in various targets. For example - in the dm-integrity target, the reboot notifier is not unregistered, leading to use-after-free. Fix this bug by refusing to resume if the device is being destroyed.
Title dm: fix resume-vs-remove race
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:22.706Z

Reserved: 2026-09-11T19:38:34.780Z

Link: CVE-2026-89997

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:10.933

Modified: 2026-09-17T10:17:05.510

Link: CVE-2026-89997

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:15:06Z

Weaknesses