{"id":"CVE-2026-89605","title":"kernel: ecryptfs: release message context on send failure (CVE-2026-89605)","summary":"A flaw was found in the `ecryptfs` component of the Linux kernel. When the `ecryptfs_send_miscdev()` function fails to send a message to the userspace daemon, the associated message context is not properly released. This oversight leaves t…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-772","vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","affected":["enterprise_linux 6"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:17:39+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89605.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89605.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89605"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532190"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89605"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89605"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89605.mbox"},{"url":"https://git.kernel.org/stable/c/177e0c32fec3602bb3b64139bb8bb610cd6722c7"},{"url":"https://git.kernel.org/stable/c/743e7aeb9575c0838d8996d40d81a6b8fa5cd060"},{"url":"https://git.kernel.org/stable/c/590fc6140e29c54d2f7839eb9df78d106ee1905e"},{"url":"https://git.kernel.org/stable/c/30845ed227475a11a49ccce047837d016b7e0f49"},{"url":"https://git.kernel.org/stable/c/47ce611cb13f0eefa550d5434c1afcd4217bfc3e"},{"url":"https://git.kernel.org/stable/c/9319706316a8e79f374627554386d575a84b637f"},{"url":"https://git.kernel.org/stable/c/654b7e79443f5ea90849f5c1cf70c0d94bd5b10e"},{"url":"https://git.kernel.org/stable/c/219644a3ad5518217b2d62cad6d2c36a2308c949"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00164,"epssPercentile":0.06026,"scores":{"vendor":5.5,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.451Z","slug":"CVE-2026-89605","body":"## Overview\n\nA flaw was found in the `ecryptfs` component of the Linux kernel. When the `ecryptfs_send_miscdev()` function fails to send a message to the userspace daemon, the associated message context is not properly released. This oversight leaves the context on an allocated list, preventing its reuse. Repeated failures could lead to resource exhaustion, potentially resulting in a Denial of Service (DoS) for the system.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 6 · no fix planned: Red Hat Enterprise Linux 6 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89605.json)\n\n**kernel: ecryptfs: release message context on send failure** — rated Low by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 6\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nOut of support scope","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208123,"id":"CVE-2026-89605","ts":1789922721673,"field":"cvss","old":"7.8","new":"5.5"},{"seq":208122,"id":"CVE-2026-89605","ts":1789922721673,"field":"severity","old":"high","new":"medium"},{"seq":197876,"id":"CVE-2026-89605","ts":1789384320774,"field":"cvss","old":"5.5","new":"7.8"},{"seq":197875,"id":"CVE-2026-89605","ts":1789384320774,"field":"severity","old":"medium","new":"high"},{"seq":183425,"id":"CVE-2026-89605","ts":1789356675317,"field":"cvss","old":"7.8","new":"5.5"},{"seq":183424,"id":"CVE-2026-89605","ts":1789356675317,"field":"severity","old":"high","new":"medium"},{"seq":153428,"id":"CVE-2026-89605","ts":1789285350472,"field":"cvss","old":null,"new":"7.8"},{"seq":153427,"id":"CVE-2026-89605","ts":1789285350472,"field":"severity","old":"none","new":"high"},{"seq":147600,"id":"CVE-2026-89605","ts":1789270211547,"field":"cvss","old":null,"new":"5.5"},{"seq":147599,"id":"CVE-2026-89605","ts":1789270211547,"field":"severity","old":"none","new":"medium"},{"seq":109366,"id":"CVE-2026-89605","ts":1789183731630,"field":"cvss","old":null,"new":"5.5"},{"seq":109365,"id":"CVE-2026-89605","ts":1789183731630,"field":"severity","old":"none","new":"medium"}]}