Linux Kernel NULL Pointer Deref in fs_bio_integrity_free (CVE-2026-89770)
CVE-2026-89770 Published on September 11, 2026
iomap: don't free integrity payload that doesn't exist
In the Linux kernel, the following vulnerability has been resolved:
iomap: don't free integrity payload that doesn't exist
fs_bio_integrity_alloc might not allocate a bio integrity payload if PI
verification is disabled on the block device. Check for that case before
calling fs_bio_integrity_free in iomap_bio_read_folio_range_sync to
avoid a NULL pointer dereferences.
Make the branch cover the PI verification as well - while
fs_bio_integrity_verify works without an integrity payload, it requires
one to actually do useful work.
Products Associated with CVE-2026-89770
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 0b10a370529cbd7b918c1eef43d409e43d9e0b78 and below 65651f1001aa3638909bc58c7b2b46160692757b is affected.
- Version 0b10a370529cbd7b918c1eef43d409e43d9e0b78 and below 8a8685b32c0718cc7b2cb4d6202e5a5b8e0a8e2d is affected.
- Version 7.1 is affected.
- Before 7.1 is unaffected.
- Version 7.2.4, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.