{"id":"CVE-2026-89748","title":"kernel: tracing: Fix retry exhaustion in simple ring buffer reader swap (CVE-2026-89748)","summary":"A flaw was found in the Linux kernel's tracing subsystem. An issue in the `simple_ring_buffer_swap_reader_page()` function, related to retry exhaustion during ring buffer reader page swaps, can lead to incorrect handling of successful or f…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-787","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:37:05+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89748.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89748.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89748"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532233"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89748"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89748"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89748.mbox"},{"url":"https://git.kernel.org/stable/c/df02489aa3aa1834659f0d20c89f7d212047d268"},{"url":"https://git.kernel.org/stable/c/e0d3aed7b12cf37b74c7cc5265073d0263b49cde"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00154,"epssPercentile":0.04911,"scores":{"vendor":6.1,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.472Z","slug":"CVE-2026-89748","body":"## Overview\n\nA flaw was found in the Linux kernel's tracing subsystem. An issue in the `simple_ring_buffer_swap_reader_page()` function, related to retry exhaustion during ring buffer reader page swaps, can lead to incorrect handling of successful or failed operations. This can result in corruption of the ring buffer, potentially causing system instability or denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89748.json)\n\n**kernel: tracing: Fix retry exhaustion in simple ring buffer reader swap** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-21.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208947,"id":"CVE-2026-89748","ts":1790062297893,"field":"cvss","old":"6.1","new":"5.5"},{"seq":202966,"id":"CVE-2026-89748","ts":1789403733147,"field":"cvss","old":"7.8","new":"6.1"},{"seq":202965,"id":"CVE-2026-89748","ts":1789403733147,"field":"severity","old":"high","new":"medium"},{"seq":197678,"id":"CVE-2026-89748","ts":1789384318357,"field":"cvss","old":"6.1","new":"7.8"},{"seq":197677,"id":"CVE-2026-89748","ts":1789384318357,"field":"severity","old":"medium","new":"high"},{"seq":183651,"id":"CVE-2026-89748","ts":1789356676263,"field":"cvss","old":"7.8","new":"6.1"},{"seq":183650,"id":"CVE-2026-89748","ts":1789356676263,"field":"severity","old":"high","new":"medium"},{"seq":153636,"id":"CVE-2026-89748","ts":1789285351651,"field":"cvss","old":null,"new":"7.8"},{"seq":153635,"id":"CVE-2026-89748","ts":1789285351651,"field":"severity","old":"none","new":"high"},{"seq":147524,"id":"CVE-2026-89748","ts":1789270211244,"field":"cvss","old":null,"new":"6.1"},{"seq":147523,"id":"CVE-2026-89748","ts":1789270211244,"field":"severity","old":"none","new":"medium"},{"seq":109270,"id":"CVE-2026-89748","ts":1789183731221,"field":"cvss","old":null,"new":"6.1"},{"seq":109269,"id":"CVE-2026-89748","ts":1789183731221,"field":"severity","old":"none","new":"medium"}]}