CVE-2026-89770EPSS p8.7%
CVE-2026-89770CVE-2026-89770
Description
In the Linux kernel, the following vulnerability has been resolved:
iomap: don't free integrity payload that doesn't exist
fs_bio_integrity_alloc might not allocate a bio integrity payload if PI
verification is disabled on the block device. Check for that case before
calling fs_bio_integrity_free in iomap_bio_read_folio_range_sync to
avoid a NULL pointer dereferences.
Make the branch cover the PI verification as well - while
fs_bio_integrity_verify works without an integrity payload, it requires
one to actually do useful work.
Scoring
| EPSS | 0.20% probability of exploitation · percentile 8.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-11 |