{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89486","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.712Z","datePublished":"2026-09-11T19:43:40.116Z","dateUpdated":"2026-09-13T06:29:55.269Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:29:55.269Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()\n\nCommit 9e91f8a6c868 (\"ipmi:msghandler: Remove srcu for the\nipmi_interfaces list\") dropped the synchronize_rcu() between unlinking\nthe command receivers from intf->cmd_rcvrs and freeing them, updating\nonly the comment that explains why the barrier is needed.\n\nThe cmd_rcvrs list is still traversed under plain RCU: find_cmd_rcvr()\nwalks it inside rcu_read_lock(), and handle_ipmb_get_msg_cmd() borrows\nrcvr->user from that lookup within the same read-side section. Without\nthe grace period, _ipmi_destroy_user() can kfree() a cmd_rcvr while a\nreader still holds a pointer to it, causing a use-after-free.\n\nThe rework only made srcu unnecessary for the interfaces list; the\ncmd_rcvrs list still relies on plain RCU. Restore the synchronize_rcu()\nbefore freeing the receivers."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached by close/release on /dev/ipmiN (ipmi_release → ipmi_destroy_user → _ipmi_destroy_user) after IPMICTL_REGISTER_FOR_CMD; BMC GET_MSG/IPMB/LAN command delivery is the RCU reader, not Linux network-packet processing, so the attack remains local like other /dev/ipmiN IPMI bugs.\nAC:L - The attacker controls the free side (open, register-for-cmd, close) and arms command watching, then races close against GET_MSG/IPMB/LAN command handling they can induce via their own IPMI ioctls and typical host-to-BMC access; this is an attacker-driven UAF race, not a layout or victim-state condition.\nPR:L - ipmi_open, ipmi_create_user, and IPMICTL_REGISTER_FOR_CMD perform no capable() check; access is only DAC on /dev/ipmiN, which server and appliance deployments routinely grant to a non-root ipmi/management group for ipmitool/freeipmi, matching established IPMI scoring.\nUI:N - The attacker opens, registers, and closes their own /dev/ipmiN file descriptors and issues ioctls themselves; no victim action such as mounting a filesystem or opening a hostile file is required.\nS:U - This is a host-kernel heap use-after-free of struct cmd_rcvr in the IPMI message handler; impact stays in the same OS security authority with no VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:H - Without synchronize_rcu(), find_cmd_rcvr() and handle_*_get_msg_cmd() read rcvr->user from a kmalloc'd cmd_rcvr that _ipmi_destroy_user() already kfree()d; reclaiming that object yields an attacker-controlled pointer and a kernel read primitive, so confidentiality is High per UAF guidance.\nI:H - A sprayed cmd_rcvr supplies a fake ipmi_user pointer; ipmi_alloc_recv_msg() then updates nr_msgs/refcount through that pointer and smi_work later invokes user->handler->ipmi_recv_hndl, enabling heap spray and control-flow hijack for arbitrary write and code execution.\nA:H - Use-after-free of cmd_rcvr during the RCU list walk and the subsequent dangling user-pointer dereference readily oopses or panics the kernel under poisoning/KASAN, so availability impact is High per UAF guidance."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/char/ipmi/ipmi_msghandler.c"],"versions":[{"version":"9e91f8a6c8688e27f4ccce7db457da87d6458836","lessThan":"3088e41292fecf132f85f79af5ee4d620b9ff1b4","status":"affected","versionType":"git"},{"version":"9e91f8a6c8688e27f4ccce7db457da87d6458836","lessThan":"5dc0b2a9af95a97861c1bffaf1687a3173e395c5","status":"affected","versionType":"git"},{"version":"9e91f8a6c8688e27f4ccce7db457da87d6458836","lessThan":"05ec76cfbce653e07cec19b9b8b20e33449d5d87","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/char/ipmi/ipmi_msghandler.c"],"versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3088e41292fecf132f85f79af5ee4d620b9ff1b4"},{"url":"https://git.kernel.org/stable/c/5dc0b2a9af95a97861c1bffaf1687a3173e395c5"},{"url":"https://git.kernel.org/stable/c/05ec76cfbce653e07cec19b9b8b20e33449d5d87"}],"title":"ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()","x_generator":{"engine":"bippy-1.2.0"}}}}