{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  fanotify: fix use-after-free of file range info  fsnotify_pre_content() builds its file_range on the triggering task's stack. fanotify_alloc_perm_event() saves a pointer to range.pos in the heap-allocated permission event so copy_range_info_to_user() can report the offset later.  The event reader can set the event state to FAN_EVENT_REPORTED and then sleep while preparing the file descriptor. If a signal interrupts the triggering task at that point, fanotify_get_response() changes the state to FAN_EVENT_CANCELED and returns. This unwinds the file_range stack frame while the reader still owns the event. The reader then dereferences pevent-\u003eppos and copies the stale stack value to userspace.  KASAN reported:    BUG: KASAN: use-after-free in fanotify_read+0x293e/0x2970   Read of size 8 at addr ffff88811434fc50 by task fanotify_inotif/95   Call Trace:    fanotify_read+0x293e/0x2970    vfs_read+0x177/0xa20    ksys_read+0xf7/0x1c0    do_syscall_64+0xf9/0x540    entry_SYSCALL_64_after_hwframe+0x77/0x7f  Store the range position directly in the permission event and use FANOTIFY_NO_RANGE when range information is unavailable. The event remains alive until the reader finishes, so the reported offset no longer depends on the triggering task's stack.",
  "id": "DEBIAN-CVE-2026-89600",
  "modified": "2026-09-14T08:47:45.931911213Z",
  "published": "2026-09-11T20:19:44.870Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89600"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89600"
  ]
}