{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89547","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.722Z","datePublished":"2026-09-11T19:44:22.644Z","dateUpdated":"2026-09-14T12:00:50.421Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:50.421Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Check svc pool percpu counter allocation\n\n__svc_create() initializes three per-pool percpu_counter stats and\nignores every return value. On SMP, percpu_counter_init() fails when\n__alloc_percpu_gfp() cannot satisfy the allocation, leaving the failed\ncounter with fbc->counters == NULL and its embedded raw_spinlock_t,\nlist_head, and count never initialized. __svc_create() returns the\nhalf-constructed svc_serv to nfsd, lockd, or the NFS callback service\nanyway.\n\nOnce that service is live, the hot-path increments in\nsvc_xprt_enqueue(), svc_handle_xprt(), and\nsvc_pool_wake_idle_thread() reach a counter whose backing pointer is\nNULL. The pointer is a per-cpu offset, so the access does not fault:\nit resolves to offset zero of the current CPU's per-cpu area and\nsilently corrupts whatever variable lives there. A\n/proc/fs/nfsd/pool_stats read walks the same NULL per-cpu storage and\nreturns garbage, and on CONFIG_DEBUG_SPINLOCK or lockdep it splats on\nthe never-initialized lock.\n\nCreating the broken service requires a percpu allocation failure during\nRPC server startup, so it is reachable only by a local administrator\nunder memory pressure or fault injection; a remote peer cannot induce\nthe bad state on its own.\n\nCheck each percpu_counter_init() return value in __svc_create() and\nfail when an allocation fails, unwinding the counters already set up\nin the current pool and in every pool initialized before it. A\ndiscrete percpu_counter_destroy() per counter at teardown frees each\nper-cpu allocation exactly once."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - After nfsd, lockd, or the NFS-callback SUNRPC service is created with a failed pool percpu_counter, svc_xprt_enqueue(), svc_handle_xprt(), and svc_pool_wake_idle_thread() increment those counters on the packet-receive hot path, so a remote NFS/NLM/callback peer triggers the corruption by sending RPC traffic (typically TCP/2049).\nAC:H - The broken service exists only if percpu_counter_init() fails inside __svc_create() during RPC server startup; that tiny per-CPU allocation failure requires memory pressure or fault injection that a remote peer cannot induce, so success depends on a startup condition the attacker cannot control.\nPR:N - svc_xprt_enqueue() and svc_handle_xprt() run when a SUNRPC transport has received data, before RPC authentication, so an unauthenticated network client needs no host account or capabilities to deliver the traffic that hits the NULL counters.\nUI:N - Exploitation is inbound RPC to an already-running nfsd, lockd, or NFS callback listener; no administrator or end-user action such as mounting a filesystem or opening a file is required at exploit time.\nS:U - Per-CPU corruption, pool_stats disclosure, and any resulting oops stay inside the host kernel's SUNRPC/nfsd authority and do not cross a VM, IOMMU, or other security boundary.\nC:H - A NULL fbc->counters pointer is treated as a per-CPU offset, so increments and percpu_counter_sum_positive() read offset 0 of each CPU's per-CPU area; world-readable nfsd pool_stats returns those values, giving a kernel-memory disclosure primitive from the same corruption.\nI:H - percpu_counter_inc() cmpxchg-increments and the batch-fold path later zeroes the s32 at per-CPU offset 0 via __this_cpu_sub(), silently corrupting whatever kernel per-CPU variable lives there and yielding a write primitive against that storage rather than a contained stats-only update.\nA:H - The never-initialized counter lock/lockdep map can splat under CONFIG_DEBUG_SPINLOCK or lockdep, and corrupting the CPU's per-CPU area can oops or panic the host, so the bug is a kernel crash/DoS even when not fully exploited."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/svc.c"],"versions":[{"version":"ccf08bed6e7a80519569456edd2ea21b7b1701c6","lessThan":"57ac7d899409b0a9b768cf417e3bb86bcca3d4c6","status":"affected","versionType":"git"},{"version":"ccf08bed6e7a80519569456edd2ea21b7b1701c6","lessThan":"3a2b7649de76376a69f1d3ed2a539fb15907cd4d","status":"affected","versionType":"git"},{"version":"ccf08bed6e7a80519569456edd2ea21b7b1701c6","lessThan":"bd1ef2cfb44d72b7aa6943e87b206eb0e30fbd0c","status":"affected","versionType":"git"},{"version":"ccf08bed6e7a80519569456edd2ea21b7b1701c6","lessThan":"b541a15046976e481618726cc23db0fb22d576db","status":"affected","versionType":"git"},{"version":"ccf08bed6e7a80519569456edd2ea21b7b1701c6","lessThan":"43e11e164704dde975c9edb370de1a06bec67270","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/svc.c"],"versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/57ac7d899409b0a9b768cf417e3bb86bcca3d4c6"},{"url":"https://git.kernel.org/stable/c/3a2b7649de76376a69f1d3ed2a539fb15907cd4d"},{"url":"https://git.kernel.org/stable/c/bd1ef2cfb44d72b7aa6943e87b206eb0e30fbd0c"},{"url":"https://git.kernel.org/stable/c/b541a15046976e481618726cc23db0fb22d576db"},{"url":"https://git.kernel.org/stable/c/43e11e164704dde975c9edb370de1a06bec67270"}],"title":"SUNRPC: Check svc pool percpu counter allocation","x_generator":{"engine":"bippy-1.2.0"}}}}