CVE-2026-89998
HIGH
Published Sep 16, 2026
Modified Sep 16, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: dm: fix race when loading and unloading a table If the userspace calls two concurrent table load ioctls and one of them succeeds and the other fails, there is a race condition because dm_setup_md_queue walks &md->table_devices without any lock. If the walk races with dm_table_destroy -> free_devices -> dm_put_table_device, there is access to invalid memory. Fix this race by extending the lock over the list walk.
Is your site exposed to CVE-2026-89998?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
7.8
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
Other References
https://git.kernel.org/stable/c/00ad6f9ed27f91925d4d3fb7aab50a60d774f998
https://git.kernel.org/stable/c/0ea6e5ad4a5817e91f11b4cc1e022e575ed2e7ca
https://git.kernel.org/stable/c/5380c7f6335cc6d77eb77d065105e81155c4d9d3
https://git.kernel.org/stable/c/a1af1884c960b98c621b6fe2fea1216b78c02152
https://git.kernel.org/stable/c/af1f32ccf8051f4691ced11feb452b9d13561727
https://git.kernel.org/stable/c/b02e35b81176c7d61dd441cc7a2e5c324a82444b
Frequently Asked Questions
What is CVE-2026-89998? +
In the Linux kernel, the following vulnerability has been resolved:
dm: fix race when loading and unloading a table
If the userspace calls two concurrent table load ioctls and one of them
succeeds and the other fails, there is a race condition because
dm_setup_md_queue walks &md->table_devices without any lock. If the walk
races with dm_table_destroy -> free_devices -> dm_put_table_device, there
is access to invalid memory.
Fix this race by extending the lock over the list walk. It has a CVSS v3.1 base score of 7.8 (HIGH).
How severe is CVE-2026-89998? +
CVE-2026-89998 has a CVSS v3.1 score of 7.8 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
How do I check if I'm vulnerable to CVE-2026-89998? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.