{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89535","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.720Z","datePublished":"2026-09-11T19:44:13.733Z","dateUpdated":"2026-09-21T13:14:22.656Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-21T13:14:22.656Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id\n\nsvc_rdma_free() caches rdma->sc_cm_id->device before teardown,\nthen calls rdma_destroy_id(sc_cm_id) which frees the cm_id.\nrpcrdma_rn_unregister() follows, but between those two calls\nthe transport's sc_rn entry is still installed in the device's\nrd_xa. A concurrent ib_unregister_device walk can dispatch\nsvc_rdma_xprt_done() against the now-freed sc_cm_id.\n\nMove rpcrdma_rn_unregister() before rdma_destroy_id() so the\ntransport's notification entry is removed from the xarray before\nthe cm_id it references is destroyed.\n\nAlso guard the sc_cm_id dereference with a NULL check: the\nfollowing patches introduce paths that reach svc_rdma_free()\nwith sc_cm_id == NULL (listener create failure, ADDR_CHANGE\nreplacement failure)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - svcrdma is nfsd's RPC-over-RDMA server transport; a remote peer over routable RoCEv2 or iWARP reaches svc_rdma_free() by disconnecting an accepted connection or by forcing the post-rpcrdma_rn_register accept-error path after CONNECT_REQUEST.\nAC:H - The UAF exists only between rdma_destroy_id() and rpcrdma_rn_unregister(); triggering it requires a concurrent ib_unregister_device xarray walk (unbind, VF hot-unplug, or rxe/siw link delete) that a remote peer cannot initiate or reliably time.\nPR:N - RDMA CM CONNECT_REQUEST, accept, and DISCONNECT run before RPC or NFS authentication, and the CM handshake has no credential check, so an unauthenticated peer can drive the teardown path.\nUI:N - Opening and dropping RPC-over-RDMA connections against an already-listening NFS/RDMA service is sufficient; concurrent administrative device removal is attack complexity, not victim user interaction.\nS:U - The use-after-free of the rdma_cm_id and any double-put of the svcxprt_rdma remain in the host kernel; this is not a VM, IOMMU, or sandbox escape.\nC:H - A concurrent rpcrdma_remove_one() walk calls svc_rdma_xprt_done(), which reads the already-freed sc_cm_id (device name and route address); a reclaimable slab UAF is confidentiality High per kernel UAF guidance.\nI:H - On the accept-failure path the same callback can svc_xprt_close() a transport whose kref is already zero, calling rdma_disconnect() on the freed cm_id and dropping the kref again, yielding a double-free/UAF write primitive.\nA:H - Dereferencing the freed rdma_cm_id or double-freeing the svcxprt_rdma causes a kernel oops or panic; any use-after-free is availability High per kernel CVSS guidance."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/xprtrdma/svc_rdma_transport.c"],"versions":[{"version":"c4de97f7c45434985e5dbf2d6ccc9eca676e37fe","lessThan":"fcd4a752ac840d39356f4d2a424d3aca4e39716b","status":"affected","versionType":"git"},{"version":"c4de97f7c45434985e5dbf2d6ccc9eca676e37fe","lessThan":"9f2f5d0999364c7070306cd422d8babc2621070d","status":"affected","versionType":"git"},{"version":"c4de97f7c45434985e5dbf2d6ccc9eca676e37fe","lessThan":"cfca6eb3345ba4a23cf9a1153ad09bf19faabfc9","status":"affected","versionType":"git"},{"version":"c4de97f7c45434985e5dbf2d6ccc9eca676e37fe","lessThan":"4488e912973773d64368828acf3b8e39d93650ae","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/xprtrdma/svc_rdma_transport.c"],"versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/fcd4a752ac840d39356f4d2a424d3aca4e39716b"},{"url":"https://git.kernel.org/stable/c/9f2f5d0999364c7070306cd422d8babc2621070d"},{"url":"https://git.kernel.org/stable/c/cfca6eb3345ba4a23cf9a1153ad09bf19faabfc9"},{"url":"https://git.kernel.org/stable/c/4488e912973773d64368828acf3b8e39d93650ae"}],"title":"svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id","x_generator":{"engine":"bippy-1.2.0"}}}}