CVE-2026-89992
HIGH
Published Sep 16, 2026
Modified Sep 16, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: cpuidle: dt_idle_genpd: kfree() the original name allocation dt_idle_pd_alloc() kasprintf()s the full node path, then points pd->name at kbasename() of that string. dt_idle_pd_free() kfree()s pd->name, which is no longer the start of the allocation. Copy the basename instead.
Is your site exposed to CVE-2026-89992?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
8.4
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
Other References
https://git.kernel.org/stable/c/09d002c8fb0261d35ce9d8a705de5db034ee90b8
https://git.kernel.org/stable/c/1312ae33b91430ec99e69cd3d47f0e50a4ebf54b
https://git.kernel.org/stable/c/2b0ac85512b7f67479127b2713254490662eb13d
https://git.kernel.org/stable/c/3394c7ba23336bdb7ece29127130fd01731d42d8
https://git.kernel.org/stable/c/a38caa9ed0d5c61c17d88393b14b292199289c1f
https://git.kernel.org/stable/c/b519dfce1998c323e54a56f911cf708d9ba0e076
Frequently Asked Questions
What is CVE-2026-89992? +
In the Linux kernel, the following vulnerability has been resolved:
cpuidle: dt_idle_genpd: kfree() the original name allocation
dt_idle_pd_alloc() kasprintf()s the full node path, then points
pd->name at kbasename() of that string. dt_idle_pd_free() kfree()s
pd->name, which is no longer the start of the allocation.
Copy the basename instead. It has a CVSS v3.1 base score of 8.4 (HIGH).
How severe is CVE-2026-89992? +
CVE-2026-89992 has a CVSS v3.1 score of 8.4 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
How do I check if I'm vulnerable to CVE-2026-89992? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.