Junglewise Threat Intelligence

CVE-2026-89595: Linux kernel fsnotify stale object mask in concurrent mark updates

CVE-2026-89595 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition in the Linux kernel's file system event notification subsystem (fsnotify) can cause event notifications to be lost when multiple monitor threads update watching rules concurrently. This affects applications relying on fanotify or inotify for file system monitoring, potentially causing missed security alerts, file integrity checks, or real-time file operation tracking.

Technical details

The vulnerability is a race condition in fsnotify's aggregate event mask calculation. When concurrent mark updates occur on the same connector, a scanning thread may read an old mark before a new event bit is added, while the updater thread reads the old aggregate mask before the scan completes. The updater then skips recalculation assuming the bit is already present, but the scan publishes a result without it, leaving the cached mask stale. This affects both fanotify and inotify. The fix ensures that mask changes trigger recalculation: for fanotify, recalculate when raw mark mask changes; always recalculate for ignore-mask and inotify watch updates. Exploitation requires concurrent updates to the same file's watch marks from multiple threads/processes.

Affected products

  • Linux Linux kernel v6.12.95 and others

Timeline

  • 2026-09-11: disclosed

Related threats