{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89510","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.716Z","datePublished":"2026-09-11T19:43:55.989Z","dateUpdated":"2026-09-14T12:00:36.409Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:36.409Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/cxgb4: Cancel reg_work before freeing device on remove\n\nc4iw_uld_state_change() queues reg_work to register the RDMA device.\nc4iw_remove() can free ctx->dev while this work is pending or running,\nleaving c4iw_register_device() accessing the freed device.\n\nCancel reg_work before removing the device.  The registration work can\ntear down ctx->dev when registration fails, so do not unregister or\ndeallocate it again in that case.\n\nThis issue was found by an in-house static analysis tool."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached from c4iw_remove() on local Chelsio T4/T5/T6 RDMA teardown (iw_cxgb4 rmmod, PCI sysfs unbind/hot-remove, EEH reset, or ULD STATE_DOWN/DETACH/FATAL). reg_work is queued from local STATE_UP (cxgb_open/uld_attach), not from c4iw_uld_rx_handler packet processing.\nAC:L - An attacker queues c4iw_register_device via STATE_UP (first cxgb_open or iw_cxgb4 load) then immediately runs c4iw_remove via unbind/rmmod/EEH, controlling both sides of the missing cancel_work_sync race and retrying bind/unbind until the worker uses freed ctx->dev; such UAFs score AC:L.\nPR:L - Per CNA driver-removal UAF precedent, an unprivileged local user on Chelsio iWARP/HPC hosts can spray the freed c4iw_dev/ib_device while privileged or automated teardown proceeds; init-namespace root is not required for the UAF itself.\nUI:N - No victim action such as mounting a filesystem or opening a file is required; the attacker queues reg_work and coordinates driver removal themselves, or piggybacks on routine PCI/module teardown.\nS:U - The use-after-free corrupts the host kernel c4iw_dev/ib_device heap object within the same security authority; it is not a VM escape, IOMMU/DMA isolation bypass, or sandbox breakout.\nC:H - After c4iw_dealloc()/ib_dealloc_device(), c4iw_register_device() still reads ctx->dev (node_guid, ports, ibdev ops) from the freed ib_device; this kernel heap UAF enables arbitrary disclosure via slab reuse.\nI:H - The dangling worker writes ibdev fields, may call ib_register_device() on freed memory, and can double-free via c4iw_dealloc(); heap spraying the ib_device ops table yields write and control-flow hijack primitives.\nA:H - Use-after-free of c4iw_dev from workqueue context during remove causes a kernel oops or panic even when not fully exploited, so availability impact is High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/cxgb4/device.c"],"versions":[{"version":"1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5","lessThan":"e6e79e7be87c5ea92728060a3d7fb56890a91e45","status":"affected","versionType":"git"},{"version":"1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5","lessThan":"672ee1981db10569ec96030bddb322f18382ec04","status":"affected","versionType":"git"},{"version":"1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5","lessThan":"4681e731db07769846901cfabdd3e53f765eb9d3","status":"affected","versionType":"git"},{"version":"1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5","lessThan":"3265d558dfafab8f12f5fba06ebbf15cae9f3225","status":"affected","versionType":"git"},{"version":"1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5","lessThan":"fe9c591026c576d8b1f72aab5e4cd67350530763","status":"affected","versionType":"git"},{"version":"1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5","lessThan":"85f438382a865a4dc4c50e6b884310bb2b60fc4d","status":"affected","versionType":"git"},{"version":"1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5","lessThan":"320e5258a53af0abc5abd9eb01519a48bab2dee8","status":"affected","versionType":"git"},{"version":"1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5","lessThan":"a7100601aa1a39f799a566acce10db20eaf4b7f2","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/cxgb4/device.c"],"versions":[{"version":"4.15","status":"affected"},{"version":"0","lessThan":"4.15","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e6e79e7be87c5ea92728060a3d7fb56890a91e45"},{"url":"https://git.kernel.org/stable/c/672ee1981db10569ec96030bddb322f18382ec04"},{"url":"https://git.kernel.org/stable/c/4681e731db07769846901cfabdd3e53f765eb9d3"},{"url":"https://git.kernel.org/stable/c/3265d558dfafab8f12f5fba06ebbf15cae9f3225"},{"url":"https://git.kernel.org/stable/c/fe9c591026c576d8b1f72aab5e4cd67350530763"},{"url":"https://git.kernel.org/stable/c/85f438382a865a4dc4c50e6b884310bb2b60fc4d"},{"url":"https://git.kernel.org/stable/c/320e5258a53af0abc5abd9eb01519a48bab2dee8"},{"url":"https://git.kernel.org/stable/c/a7100601aa1a39f799a566acce10db20eaf4b7f2"}],"title":"RDMA/cxgb4: Cancel reg_work before freeing device on remove","x_generator":{"engine":"bippy-1.2.0"}}}}