Skip to main content

In the Linux kernel, the following vulnerability has been resolved: eventfs: Initialize ei->children and ei->list in init_ei() eventfs_create_dir()… (CVE-2026-89618)

0
Low
Published: 09/11/2026 (09/11/2026, 21:31:34 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's eventfs subsystem was resolved by properly initializing list pointers in the init_ei() function. The issue involved uninitialized list_heads in eventfs_inode structures, which could cause false warnings during error handling when eventfs_create_dir() fails due to memory pressure.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 01:00:31 UTC

Technical Analysis

The Linux kernel's eventfs_create_dir() function allocates an eventfs_inode and initializes it with init_ei(). However, the list_heads (ei->children and ei->list) were not initialized in init_ei(), leading to potential false warnings in free_ei() when eventfs_create_dir() fails and attempts to verify that the inode has no children. The fix involved moving the initialization of these list pointers into init_ei(), ensuring proper setup before any error handling occurs.

Potential Impact

The vulnerability causes false warnings during error handling in eventfs_create_dir() when memory allocation fails. There is no indication of security impact such as privilege escalation, denial of service, or information disclosure. The issue is primarily related to incorrect internal state handling.

Mitigation Recommendations

A fix has been implemented by moving the initialization of the list_heads into the init_ei() function. Users should apply the updated Linux kernel patch that includes this fix. No additional mitigation steps are indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-jw9q-gp66-86rq
Osv Schema Version
1.4.0
Aliases
["CVE-2026-89618"]

Threat ID: 6aa4a00855bf5e2cf5a86653

Added to database: 09/12/2026, 00:42:48 UTC

Last enriched: 09/12/2026, 01:00:31 UTC

Last updated: 09/12/2026, 01:49:48 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses