{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-81004","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.812Z","datePublished":"2026-09-11T19:42:56.813Z","dateUpdated":"2026-09-13T06:29:08.664Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:29:08.664Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipmi:msghandler: Cancel work cleanly on an error\n\nIf an error occurs during startup of an IPMI interface, it may have\nscheduled work to run.  The work needs to be canceled before the\ninterface can be freed."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - ipmi_add_smi() is reached from host-local IPMI system-interface probe (ipmi_si/SSIF/IPMB/PowerNV), not from Linux network-packet processing; a compromised BMC still talks over KCS/SMIC/BT/SSIF/IPMB on the platform, so the attack remains local.\nAC:L - When the lower-layer sender() fails during startup Get Device ID or channel scan, smi_send() queues intf->smi_work and returns an error; ipmi_add_smi() then frees the interface without cancel_work_sync, so a BMC that returns a bus error deterministically leaves work pending on a freed object.\nPR:N - The vulnerable path runs during automatic SMI registration at boot or device probe; a compromised BMC can fail sender() or Get Device ID after work is queued with no host login, capability, or /dev/ipmiN access.\nUI:N - Driver probe and BMC responses occur without a victim mounting a filesystem, opening a device node, or otherwise interacting.\nS:U - The use-after-free is of host-kernel struct ipmi_smi in the IPMI message handler; it is a standard in-kernel UAF, not a VM escape, IOMMU bypass, or sandbox breakout.\nC:H - smi_work() recovers the freed ipmi_smi via from_work and reads its queues, flags, and handler pointers from reclaimed slab memory, yielding an arbitrary kernel read primitive per UAF guidance.\nI:H - smi_work() invokes intf->handlers->sender on the freed interface, so a heap-sprayed object can hijack that function pointer for arbitrary write and control-flow hijack.\nA:H - Running queued smi_work after kfree(intf) in intf_free() dereferences freed memory and readily oopses or panics the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/char/ipmi/ipmi_msghandler.c"],"versions":[{"version":"edb6c2118293c1fba9cd11ca80ed043d2411a7e5","lessThan":"99692252b348c11377fd0cdd66b6b18f3b22758e","status":"affected","versionType":"git"},{"version":"62cd145453d577113f993efd025f258dd86aa183","lessThan":"a496c51dd3257ed7e00873af2ad9bb22c3ddc4cf","status":"affected","versionType":"git"},{"version":"62cd145453d577113f993efd025f258dd86aa183","lessThan":"ae84a2536577057e97f23f75a202e26d0e86cf01","status":"affected","versionType":"git"},{"version":"5199fc5dc9c519115457406009fcefd50721c995","status":"affected","versionType":"git"},{"version":"6.18.20","lessThan":"6.18.50","status":"affected","versionType":"semver"},{"version":"6.19.10","lessThan":"6.20","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/char/ipmi/ipmi_msghandler.c"],"versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18.20","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19.10"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/99692252b348c11377fd0cdd66b6b18f3b22758e"},{"url":"https://git.kernel.org/stable/c/a496c51dd3257ed7e00873af2ad9bb22c3ddc4cf"},{"url":"https://git.kernel.org/stable/c/ae84a2536577057e97f23f75a202e26d0e86cf01"}],"title":"ipmi:msghandler: Cancel work cleanly on an error","x_generator":{"engine":"bippy-1.2.0"}}}}