Linux Kernel Vulnerability in Trusted Key Management
CVE-2026-89763
What is CVE-2026-89763?
A vulnerability in the Linux kernel's trusted key management system allows for a use-after-free condition during the teardown of the TPM (Trusted Platform Module) subsystem. The issue arises from an improper ordering in the cleanup process, where the TPM reference and associated digest array are released before the trusted key type is unregistered. This flaw can lead to dereferencing a freed memory space during key operations, posing a risk of unauthorized memory access and stability issues. The vulnerability has been addressed by rearranging the teardown sequence to ensure all key operations are completed before freeing resources.
Affected Version(s)
Linux 0b6cf6b97b7ef1fa3c7fefab0cac897a1c4a3400 < 753c978f2400f9783eb524842a975d3ac950d511
Linux 0b6cf6b97b7ef1fa3c7fefab0cac897a1c4a3400 < 2f7541afbc57fe9d26769a22c31d8ce8790c9a19
Linux 0b6cf6b97b7ef1fa3c7fefab0cac897a1c4a3400 < 5e2d672280d97d83de43031d93761b12dadd7b8a