---
id: CVE-2026-89763
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  KEYS: trusted: Fix TPM teardown ordering

  trusted_tpm_exit() drops the TPM chip reference and frees the digest
  array before unregistering the trusted key type
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  KEYS: trusted: Fix TPM teardown ordering

  trusted_tpm_exit() drops the TPM chip reference and frees the digest
  array before unregistering the trusted key type. key_type…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-825
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 0b6cf6b97b7ef1fa3c7fefab0cac897a1c4a3400 <
    3d67b4acbfc7af331d887a8efc04bef6573b8a7a
  - >-
    Linux >= 0b6cf6b97b7ef1fa3c7fefab0cac897a1c4a3400 <
    753c978f2400f9783eb524842a975d3ac950d511
  - >-
    Linux >= 0b6cf6b97b7ef1fa3c7fefab0cac897a1c4a3400 <
    2f7541afbc57fe9d26769a22c31d8ce8790c9a19
  - >-
    Linux >= 0b6cf6b97b7ef1fa3c7fefab0cac897a1c4a3400 <
    5e2d672280d97d83de43031d93761b12dadd7b8a
  - Linux 5.1
published: '2026-09-11'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T14:17:26.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89763'
references:
  - url: 'https://git.kernel.org/stable/c/2f7541afbc57fe9d26769a22c31d8ce8790c9a19'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3d67b4acbfc7af331d887a8efc04bef6573b8a7a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5e2d672280d97d83de43031d93761b12dadd7b8a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/753c978f2400f9783eb524842a975d3ac950d511'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89763.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89763'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532156'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89763'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89763'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89763.mbox
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - score-dispute
epss: 0.0017
epssPercentile: 0.05582
scores:
  nvd: 7.8
  cna: 7.8
  vendor: 5.5
ingestedAt: '2026-09-14T15:23:07.472Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

KEYS: trusted: Fix TPM teardown ordering

trusted_tpm_exit() drops the TPM chip reference and frees the digest
array before unregistering the trusted key type. key_type_lookup()
holds key_types_sem for reading until the key operation finishes, while
unregister_key_type() takes it for writing. It therefore provides the
synchronization point that must precede backend teardown.

The current order permits this interleaving:

  CPU 0                              CPU 1
  trusted_tpm_exit()                 key_type_lookup("trusted")
    put_device(&chip->dev)             trusted_tpm_seal()
    kfree(digests)                       pcrlock()
    unregister_key_type()                  tpm_pcr_extend(..., digests)

CPU 1 can consequently dereference the freed digest array. The chip can
also be released before callbacks stop using it.

KASAN reported:

  BUG: KASAN: slab-use-after-free in tpm_pcr_extend+0x1f0/0x200
  Read of size 2 at addr ffff88810872d000 by task poc/89
  Call Trace:
    tpm_pcr_extend+0x1f0/0x200
    pcrlock+0x42/0x70 [trusted]
    trusted_tpm_seal+0x1b6/0x570 [trusted]
    trusted_instantiate+0x293/0x340 [trusted]
    __key_instantiate_and_link+0xb2/0x2b0
    __key_create_or_update+0x61e/0xb50
    __do_sys_add_key+0x1b8/0x310
  Allocated by task 88:
    __kmalloc_noprof+0x1a7/0x490
    do_one_initcall+0xa1/0x390
    do_init_module+0x2df/0x840
  Freed by task 90:
    kfree+0x131/0x3c0
    trusted_tpm_exit+0x59/0xa0 [trusted]
    __do_sys_delete_module+0x346/0x510

Move unregister_key_type() before releasing either resource. This stops
new lookups and waits for in-flight key operations to finish before the
backend state is destroyed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89763.json)
