---
id: CVE-2026-89496
title: >-
  kernel: ocfs2: always run deallocs on copy-on-write completion
  (CVE-2026-89496)
summary: >-
  A flaw was found in ocfs2, the Oracle Cluster File System, within the Linux
  kernel. A local user could exploit this vulnerability by performing a
  `copy_file_range()` operation within the same filesystem. This can lead to a
  memory leak, pot…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-772
vendor: Red Hat
product: Linux
affected:
  - >-
    Linux >= 6f70fa519976a379d72781d927cf8e5f5b05ec86 <
    5ff30f07def6d0e6edacf47952807b5ff60f3af6
  - >-
    Linux >= 6f70fa519976a379d72781d927cf8e5f5b05ec86 <
    2753e12853ed2023555cec2c5fe22fbaabb2c0b7
  - >-
    Linux >= 6f70fa519976a379d72781d927cf8e5f5b05ec86 <
    f0261b3aca027f5c409a402ea22f6982750f911c
  - >-
    Linux >= 6f70fa519976a379d72781d927cf8e5f5b05ec86 <
    a4adaa722977f46511d4247172cd4ec991b80ff2
  - >-
    Linux >= 6f70fa519976a379d72781d927cf8e5f5b05ec86 <
    123c050eb96aae0bab74c9f06c6ad3de7992722b
  - >-
    Linux >= 6f70fa519976a379d72781d927cf8e5f5b05ec86 <
    71f07b7f90b3109c9098d1b9c8efbbeece5deb8a
  - >-
    Linux >= 6f70fa519976a379d72781d927cf8e5f5b05ec86 <
    09e93a60e18e83a630ff84ae00cb564bab96ab1f
  - >-
    Linux >= 6f70fa519976a379d72781d927cf8e5f5b05ec86 <
    82ea9d4fc05fb7a387db547c6a7c0aa6a3719616
  - Linux 2.6.32
published: '2026-09-11'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T07:07:03+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89496.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89496.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89496'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532512'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89496'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89496'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89496.mbox
  - url: 'https://git.kernel.org/stable/c/5ff30f07def6d0e6edacf47952807b5ff60f3af6'
  - url: 'https://git.kernel.org/stable/c/2753e12853ed2023555cec2c5fe22fbaabb2c0b7'
  - url: 'https://git.kernel.org/stable/c/f0261b3aca027f5c409a402ea22f6982750f911c'
  - url: 'https://git.kernel.org/stable/c/a4adaa722977f46511d4247172cd4ec991b80ff2'
  - url: 'https://git.kernel.org/stable/c/123c050eb96aae0bab74c9f06c6ad3de7992722b'
  - url: 'https://git.kernel.org/stable/c/71f07b7f90b3109c9098d1b9c8efbbeece5deb8a'
  - url: 'https://git.kernel.org/stable/c/09e93a60e18e83a630ff84ae00cb564bab96ab1f'
  - url: 'https://git.kernel.org/stable/c/82ea9d4fc05fb7a387db547c6a7c0aa6a3719616'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.0022
epssPercentile: 0.11031
ingestedAt: '2026-09-14T15:23:07.452Z'
---

## Overview

A flaw was found in ocfs2, the Oracle Cluster File System, within the Linux kernel. A local user could exploit this vulnerability by performing a `copy_file_range()` operation within the same filesystem. This can lead to a memory leak, potentially causing resource exhaustion and a Denial of Service (DoS) on the system.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89496.json)

**kernel: ocfs2: always run deallocs on copy-on-write completion** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
