{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89534","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.720Z","datePublished":"2026-09-11T19:44:12.987Z","dateUpdated":"2026-09-13T06:30:31.103Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:30:31.103Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails\n\nWhen svc_rdma_listen_handler() handles RDMA_CM_EVENT_ADDR_CHANGE,\nit creates a replacement listener cm_id and returns 1, telling\nthe CM core to destroy the old one. If the replacement allocation\nfails, sc_cm_id still points at the old cm_id that the CM core is\nabout to destroy. Any subsequent dereference of sc_cm_id --\nsuch as svc_rdma_detach()'s rdma_disconnect() call -- is a\nuse-after-free.\n\nNULL sc_cm_id on the failure path and guard svc_rdma_detach()'s\nrdma_disconnect() call against NULL so that the listener can\nbe torn down safely when the server shuts down."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - svcrdma is the in-kernel NFS/RDMA server listen path; RDMA_CM_EVENT_ADDR_CHANGE is raised only from cma_netdev_callback on NETDEV_BONDING_FAILOVER when the bound bond MAC changes, so an attacker on the RoCE/IB storage fabric inducing active-backup failover reaches the bug, matching ADDR_CHANGE scoring for RPC-over-RDMA.\nAC:L - svc_rdma_create_listen_id() binds the replacement while the old listen cm_id still owns the port, so rdma_bind_addr() fails deterministically with EADDRINUSE/EADDRNOTAVAIL; the handler still returns 1 and the CM core frees that id, leaving a dangling sc_cm_id the attacker can arm by inducing failover.\nPR:N - The NFS/RDMA listener is already running as a network service; bonding failover and RDMA CM ADDR_CHANGE delivery perform no RPC, NFS export, or other authentication, so an adjacent fabric attacker needs no account or capability on the victim host.\nUI:N - Exploitation uses attacker-induced link failover plus subsequent listener teardown (nfsd restart/shutdown, the normal operational response once the listen endpoint is dead); no separate victim action such as mounting a filesystem or opening a file is required.\nS:U - The use-after-free corrupts the host kernel rdma_cm_id/rdma_id_private object used by nfsd's RDMA transport in the same kernel security authority and is not a VM, IOMMU, or sandbox escape.\nC:H - After the CM core destroys the listen id, sc_cm_id is a dangling pointer to a freed rdma_cm_id with an event_handler; later rdma_disconnect()/rdma_destroy_id() in svc_rdma_detach/free is a kernel heap UAF that enables arbitrary disclosure via controlled reuse.\nI:H - svc_rdma_detach() calls rdma_disconnect() on the freed cm_id and svc_rdma_free() may rdma_destroy_id() it again, yielding UAF writes, double-free, and function-pointer hijack of event_handler, so integrity impact is High per UAF guidance.\nA:H - Use-after-free of the listen rdma_cm_id during detach/free causes a kernel oops or panic even when not fully exploited, so availability impact is High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/xprtrdma/svc_rdma_transport.c"],"versions":[{"version":"d1b586e75ec619dde1af47e21a41a6b1b51874c2","lessThan":"673e358ab7c11f8cec223c6a36a793056a67facd","status":"affected","versionType":"git"},{"version":"d1b586e75ec619dde1af47e21a41a6b1b51874c2","lessThan":"01500306e1d50de7ca7a2cdcdfa28ac0523eb747","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/xprtrdma/svc_rdma_transport.c"],"versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/673e358ab7c11f8cec223c6a36a793056a67facd"},{"url":"https://git.kernel.org/stable/c/01500306e1d50de7ca7a2cdcdfa28ac0523eb747"}],"title":"svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails","x_generator":{"engine":"bippy-1.2.0"}}}}