Junglewise Threat Intelligence

CVE-2026-89793: Linux kernel ublk privilege escalation via VM_MAYWRITE

CVE-2026-89793 · Severity: high · CVSS 7.8 · Published 2026-09-16

Executive brief

The Linux kernel's ublk (userspace block device) driver improperly manages memory mapping permissions, allowing unprivileged daemon processes to escalate privileges and corrupt kernel-controlled data structures. An attacker can memory-map a read-only command buffer, then use mprotect() to upgrade it to writable access, enabling modification of critical I/O descriptors that control block device operations.

Technical details

This is a privilege escalation vulnerability in the ublk driver's character device mmap handler (ublk_ch_mmap). The vulnerable code rejects initial mmap requests with VM_WRITE set but fails to clear the VM_MAYWRITE flag, which permits later privilege elevation via mprotect(). An unprivileged daemon can exploit this to obtain write access to the per-queue command buffer containing kernel-written struct ublksrv_io_desc entries. A successful exploit allows corruption of fields such as addr, op_flags, nr_sectors, and start_sector, effectively giving the daemon arbitrary control over block I/O operations. The vulnerability requires local access to the ublk character device but no special privileges. A fix has been committed to the Linux kernel (upstream commit 6e2b571b0a54755b06e092501913e1dfefe75d6c) that clears VM_MAYWRITE to prevent mprotect() upgrades.

Affected products

  • Linux Linux kernel all versions with ublk driver (since Linux 6.0 approximately)

Timeline

  • 2026-09-16: disclosed: Published via NVD
  • 2026-09-01: patched: Upstream fix committed by Jens Axboe
  • 2026-09-14: patched: Fix included in stable kernel tree by Greg Kroah-Hartman

References

Related threats