---
id: CVE-2026-89989
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()

  dentry_path() returns ERR_PTR(-ENAMETOOLONG) when the path exceeds the
  buffer
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()

  dentry_path() returns ERR_PTR(-ENAMETOOLONG) when the path exceeds the
  buffer. validate_hash_algo() p…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 4f2946aa0c45c78b4f4ef101bab9694e38c68db0 <
    d6fade89903c8fd0af6c956242aec8b927040e02
  - >-
    Linux >= 4f2946aa0c45c78b4f4ef101bab9694e38c68db0 <
    0de5b525c0cd7d202848b8adfde3c01c287fb1a6
  - >-
    Linux >= 4f2946aa0c45c78b4f4ef101bab9694e38c68db0 <
    30b5c0e17dcad72b6b2f987319aa645570e6376d
  - >-
    Linux >= 4f2946aa0c45c78b4f4ef101bab9694e38c68db0 <
    9e69d683ebd7def04557fe758ff123105d7d9840
  - >-
    Linux >= 4f2946aa0c45c78b4f4ef101bab9694e38c68db0 <
    f8a2f2a4602318eb93d49d27fd0d0fdaab17edde
  - >-
    Linux >= 4f2946aa0c45c78b4f4ef101bab9694e38c68db0 <
    d62a84a78de5f29c642fa3bd4eee072ba7289cb4
  - >-
    Linux >= 4f2946aa0c45c78b4f4ef101bab9694e38c68db0 <
    8861f6d5c0678a7c5089c7b272509fc5931b8437
  - Linux 5.15
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T11:17:10.010'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89989'
references:
  - url: 'https://git.kernel.org/stable/c/0de5b525c0cd7d202848b8adfde3c01c287fb1a6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/30b5c0e17dcad72b6b2f987319aa645570e6376d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8861f6d5c0678a7c5089c7b272509fc5931b8437'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9e69d683ebd7def04557fe758ff123105d7d9840'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d62a84a78de5f29c642fa3bd4eee072ba7289cb4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d6fade89903c8fd0af6c956242aec8b927040e02'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f8a2f2a4602318eb93d49d27fd0d0fdaab17edde'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T10:53:53.949Z'
epss: 0.00205
epssPercentile: 0.10894
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()

dentry_path() returns ERR_PTR(-ENAMETOOLONG) when the path exceeds the
buffer. validate_hash_algo() passes the result straight to
integrity_audit_msg() without checking. ERR_PTR is not NULL, so
integrity_audit_message() sees a valid pointer and calls strlen() on
it, which faults:

    BUG: unable to handle page fault for address: ffffffffffffffdc
    RIP: 0010:strlen+0x30/0xa0
    Call Trace:
     audit_log_untrustedstring+0x19/0x30
     integrity_audit_message+0x366/0x4f0
     ima_inode_setxattr+0x512/0x5f0

Check for IS_ERR() and use NULL instead, which makes the audit message
skip the name= field instead of crashing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
