{"id":"CVE-2026-89446","title":"kernel: iommufd: Release current IOAS on xa_store() failure (CVE-2026-89446)","summary":"A flaw was found in the Linux kernel's iommufd component. When the system attempts to store an Input/Output Address Space (IOAS) object and the storage operation fails, the IOAS object's associated resources, such as its write lock and obj…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-772","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:55:06+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89446.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89446.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89446"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532091"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89446"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89446"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89446.mbox"},{"url":"https://git.kernel.org/stable/c/4c33d00ad9a911e87ea222986f732ce072e3aa26"},{"url":"https://git.kernel.org/stable/c/07b4fe1367f076886c1c47a19c70936138325087"},{"url":"https://git.kernel.org/stable/c/4ac2ce123824d5f885c868fa1f9f4d463141a2ba"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00198,"epssPercentile":0.09823,"ingestedAt":"2026-09-14T00:35:28.531Z","slug":"CVE-2026-89446","body":"## Overview\n\nA flaw was found in the Linux kernel's iommufd component. When the system attempts to store an Input/Output Address Space (IOAS) object and the storage operation fails, the IOAS object's associated resources, such as its write lock and object reference, are not properly released. This oversight can lead to a resource leak, which a local attacker could potentially exploit to cause a Denial of Service (DoS) condition due to resource exhaustion.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89446.json)\n\n**kernel: iommufd: Release current IOAS on xa_store() failure** — rated Low by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":206998,"id":"CVE-2026-89446","ts":1789749736311,"field":"cvss","old":null,"new":"5.5"},{"seq":206997,"id":"CVE-2026-89446","ts":1789749736311,"field":"severity","old":"none","new":"medium"},{"seq":147730,"id":"CVE-2026-89446","ts":1789270212068,"field":"cvss","old":null,"new":"4.4"},{"seq":147729,"id":"CVE-2026-89446","ts":1789270212068,"field":"severity","old":"none","new":"medium"},{"seq":109482,"id":"CVE-2026-89446","ts":1789183732085,"field":"cvss","old":null,"new":"4.4"},{"seq":109481,"id":"CVE-2026-89446","ts":1789183732085,"field":"severity","old":"none","new":"medium"}]}