{"id":"CVE-2026-89757","title":"kernel: mm/mglru: fix and remove redundant unevictable folio handling (CVE-2026-89757)","summary":"A flaw was found in the Linux kernel's memory management unit (MMU), specifically within the multi-generational Least Recently Used (mglru) mechanism. A bug in how the kernel handles unevictable memory pages can lead to these pages remaini…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-911","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 6","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-15","sourceUpdated":"2026-09-15T18:46:07+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89757.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89757.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89757"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532135"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89757"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89757"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89757.mbox"},{"url":"https://git.kernel.org/stable/c/15d3a2a71c8bf7333d019d249ee33669e69e4275"},{"url":"https://git.kernel.org/stable/c/54a58d6656dd403b686b247f0bad8507cbfb45df"},{"url":"https://git.kernel.org/stable/c/f7e698e326b239a91ea15844817551921209e826"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00184,"epssPercentile":0.08229,"ingestedAt":"2026-09-14T11:11:19.884Z","slug":"CVE-2026-89757","body":"## Overview\n\nA flaw was found in the Linux kernel's memory management unit (MMU), specifically within the multi-generational Least Recently Used (mglru) mechanism. A bug in how the kernel handles unevictable memory pages can lead to these pages remaining locked in memory even after they should be released. This can result in inflated memory accounting and potentially lead to unexpected system behavior or resource exhaustion, impacting system stability.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89757.json)\n\n**kernel: mm/mglru: fix and remove redundant unevictable folio handling** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nOut of support scope","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":205531,"id":"CVE-2026-89757","ts":1789576723652,"field":"cvss","old":"5.3","new":"5.5"},{"seq":204081,"id":"CVE-2026-89757","ts":1789490231356,"field":"cvss","old":null,"new":"5.3"},{"seq":204080,"id":"CVE-2026-89757","ts":1789490231356,"field":"severity","old":"none","new":"medium"},{"seq":147680,"id":"CVE-2026-89757","ts":1789270211857,"field":"cvss","old":null,"new":"5.3"},{"seq":147679,"id":"CVE-2026-89757","ts":1789270211857,"field":"severity","old":"none","new":"medium"},{"seq":109436,"id":"CVE-2026-89757","ts":1789183731907,"field":"cvss","old":null,"new":"5.3"},{"seq":109435,"id":"CVE-2026-89757","ts":1789183731907,"field":"severity","old":"none","new":"medium"}]}