---
id: CVE-2026-89605
title: 'kernel: ecryptfs: release message context on send failure (CVE-2026-89605)'
summary: >-
  A flaw was found in the `ecryptfs` component of the Linux kernel. When the
  `ecryptfs_send_miscdev()` function fails to send a message to the userspace
  daemon, the associated message context is not properly released. This
  oversight leaves t…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-772
vendor: Red Hat
product: Red Hat Enterprise Linux 6
affected:
  - enterprise_linux 6
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:17:39+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89605.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89605.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89605'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532190'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89605'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89605'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89605.mbox
  - url: 'https://git.kernel.org/stable/c/177e0c32fec3602bb3b64139bb8bb610cd6722c7'
  - url: 'https://git.kernel.org/stable/c/743e7aeb9575c0838d8996d40d81a6b8fa5cd060'
  - url: 'https://git.kernel.org/stable/c/590fc6140e29c54d2f7839eb9df78d106ee1905e'
  - url: 'https://git.kernel.org/stable/c/30845ed227475a11a49ccce047837d016b7e0f49'
  - url: 'https://git.kernel.org/stable/c/47ce611cb13f0eefa550d5434c1afcd4217bfc3e'
  - url: 'https://git.kernel.org/stable/c/9319706316a8e79f374627554386d575a84b637f'
  - url: 'https://git.kernel.org/stable/c/654b7e79443f5ea90849f5c1cf70c0d94bd5b10e'
  - url: 'https://git.kernel.org/stable/c/219644a3ad5518217b2d62cad6d2c36a2308c949'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00176
epssPercentile: 0.06323
scores:
  vendor: 5.5
  cna: 7.8
ingestedAt: '2026-09-14T15:23:07.451Z'
---

## Overview

A flaw was found in the `ecryptfs` component of the Linux kernel. When the `ecryptfs_send_miscdev()` function fails to send a message to the userspace daemon, the associated message context is not properly released. This oversight leaves the context on an allocated list, preventing its reuse. Repeated failures could lead to resource exhaustion, potentially resulting in a Denial of Service (DoS) for the system.

## Vendor advisories

- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 6 · no fix planned: Red Hat Enterprise Linux 6 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89605.json)

**kernel: ecryptfs: release message context on send failure** — rated Low by Red Hat. Released 2026-09-11, updated 2026-09-18.

Affected:

- Red Hat Enterprise Linux 6

No fix planned:

- Red Hat Enterprise Linux 6

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Out of support scope
