← All Advisories

CVE-2026-89763

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89763

Key Details

CVECVE-2026-89763
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

KEYS: trusted: Fix TPM teardown ordering

trusted_tpm_exit() drops the TPM chip reference and frees the digest

array before unregistering the trusted key type. key_type_lookup()

holds key_types_sem for reading until the key operation finishes, while

unregister_key_type() takes it for writing. It therefore provides the

synchronization point that must precede backend teardown.

The current order permits this interleaving:

CPU 0 CPU 1

trusted_tpm_exit() key_type_lookup("trusted")

put_device(&chip->dev) trusted_tpm_seal()

kfree(digests) pcrlock()

unregister_key_type() tpm_pcr_extend(..., digests)

CPU 1 can consequently dereference the freed digest array. The chip can

also be released before callbacks stop using it.

KASAN reported:

BUG: KASAN: slab-use-after-free in tpm_pcr_extend+0x1f0/0x200

Read of size 2 at addr ffff88810872d000 by task poc/89

Call Trace:

tpm_pcr_extend+0x1f0/0x200

pcrlock+0x42/0x70 [trusted]

trusted_tpm_seal+0x1b6/0x570 [trusted]

trusted_instantiate+0x293/0x340 [trusted]

__key_instantiate_and_link+0xb2/0x2b0

__key_create_or_update+0x61e/0xb50

__do_sys_add_key+0x1b8/0x310

Allocated by task 88:

__kmalloc_noprof+0x1a7/0x490

do_one_initcall+0xa1/0x390

do_init_module+0x2df/0x840

Freed by task 90:

kfree+0x131/0x3c0

trusted_tpm_exit+0x59/0xa0 [trusted]

__do_sys_delete_module+0x346/0x510

Move unregister_key_type() before releasing either resource. This stops

new lookups and waits for in-flight key operations to finish before the

backend state is destroyed. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89763
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89763