{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89507","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.716Z","datePublished":"2026-09-11T19:43:54.013Z","dateUpdated":"2026-09-13T06:30:12.335Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:30:12.335Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/ucma: Lock the handler in ucma_write_cm_event()\n\nctx->file may only be changed under the handler lock and the xa_lock, which\nis what stops uevents being queued for a ctx while ucma_migrate_id() moves\nit to another file.  The CM core takes that lock before invoking\nucma_event_handler(), but the write() paths that queue uevents themselves\ndo not.\n\nucma_write_cm_event() re-reads ctx->file for each of its four dereferences,\nso ucma_migrate_id() can swap it mid-sequence:\n\n\tmutex_lock(&ctx->file->mut);\t\t\t/* file A */\n\tlist_add_tail(&uevent->list, &ctx->file->event_list);\t/* file B */\n\tmutex_unlock(&ctx->file->mut);\t\t\t/* file B */\n\twake_up_interruptible(&ctx->file->poll_wait);\t/* file B */\n\nThe window is the mutex_lock() itself: the writer sleeps in it while the\nmigration reassigns ctx->file.  The list_add_tail() then runs on file B's\nevent_list holding only file A's mutex:\n\n  list_add corruption. prev->next should be next (ffff888101320f30),\n    but was ffff88814a08c418. (prev=ffff88814a075c18).\n  kernel BUG at lib/list_debug.c:32!\n  Call Trace:\n   ucma_write_cm_event+0x36e/0x5e0\n\nand file A's mut is left held forever, wedging its next writer in D state.\nThe uevent is also stranded on a list ucma_cleanup_ctx_events() will not\nwalk, so it outlives its context.  /dev/infiniband/rdma_cm is 0666 and no\nRDMA device is involved, so an unprivileged user reaches all of this.\n\nTake the handler lock, as ucma_cleanup_mc_events() does; ctx->cm_id is\npinned by the ucma_get_ctx() reference."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Reached by write() on the local misc device /dev/infiniband/rdma_cm (ucma_write → WRITE_CM_EVENT racing MIGRATE_ID). Remote RDMA CM packet handling already takes the handler lock in ucma_event_handler(), so this bug is not a network-packet path.\nAC:L - The attacker fully controls both sides of the race: one thread issues WRITE_CM_EVENT while another issues MIGRATE_ID on the same ctx, and can hold file A's mutex from a third thread so the writer sleeps in mutex_lock() across ctx->file reassignment.\nPR:L - ucma registers /dev/infiniband/rdma_cm with mode 0666 and the command path (create_id, write_cm_event, migrate_id) has no capability checks. No RDMA hardware is required (ucma_get_ctx, not ucma_get_ctx_dev), so any unprivileged local user can open the device and trigger the bug.\nUI:N - Exploitation uses only the attacker's own open/write syscalls against rdma_cm; no other user or administrator action is required.\nS:U - This is in-kernel list corruption and use-after-free within the host kernel's security authority. It can escalate privileges on the host but does not cross a VM, IOMMU, or sandbox boundary.\nC:H - The unlocked list_add can strand a uevent on another file's list so it outlives its ucma_context, and concurrent GET_EVENT can free a ucma_event still being linked (UAF). Per UAF guidance that enables attacker-controlled reuse and arbitrary kernel reads.\nI:H - list_add_tail on file B's event_list while holding only file A's mutex, plus mutex_unlock of an unheld mutex, corrupts kernel lists; combined with UAF of ctx/uevent this yields heap-sprayable write and list-unlink primitives for control-flow hijacking.\nA:H - The race was reproduced as kernel BUG at lib/list_debug.c:32 in ucma_write_cm_event, and file A's mutex is left held forever wedging later writers in D-state. UAFs also oops, so availability impact is high even without full exploitation."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/ucma.c"],"versions":[{"version":"a3c9d0fcd3715541bbf97da2ddde9d032e2fe6d5","lessThan":"4f8bb11dd2ff365e7cff1c9964ab4607292d364e","status":"affected","versionType":"git"},{"version":"a3c9d0fcd3715541bbf97da2ddde9d032e2fe6d5","lessThan":"0be1955040a2eceed0ecfc387fdc92305411d273","status":"affected","versionType":"git"},{"version":"a3c9d0fcd3715541bbf97da2ddde9d032e2fe6d5","lessThan":"f4cc21c6a8e9d392871477f9fd98d68e5ad80272","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/ucma.c"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/4f8bb11dd2ff365e7cff1c9964ab4607292d364e"},{"url":"https://git.kernel.org/stable/c/0be1955040a2eceed0ecfc387fdc92305411d273"},{"url":"https://git.kernel.org/stable/c/f4cc21c6a8e9d392871477f9fd98d68e5ad80272"}],"title":"RDMA/ucma: Lock the handler in ucma_write_cm_event()","x_generator":{"engine":"bippy-1.2.0"}}}}