{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89549","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.723Z","datePublished":"2026-09-11T19:44:23.928Z","dateUpdated":"2026-09-14T12:00:52.566Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:52.566Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: route to a populated pool in svc_pool_for_cpu()\n\nsvc_set_num_threads() spreads the requested threads evenly across the\nservice's pools (base = nrservs / sv_nrpools).  When a service runs\nfewer threads than it has pools -- e.g. an nfsd configured with fewer\nthreads than the host has NUMA nodes while running in \"pernode\" or\n\"percpu\" mode -- the trailing pools are left with no threads at all.\n\nsvc_xprt_enqueue() selects a pool from the CPU servicing the transport,\nqueues the transport on that pool's sp_xprts, and only wakes a thread\nfrom the same pool.  Each thread services exclusively its own pool, so a\ntransport that lands on a threadless pool is enqueued on sp_xprts and\nnever picked up: the connection hangs indefinitely.\n\nHave svc_pool_for_cpu() skip pools that currently have no threads,\nfalling back to the next populated pool.  This trades NUMA locality for\na guarantee that the work is actually serviced.  sp_nrthreads is only\nupdated under the service mutex; the lockless read here is a best-effort\nrouting hint, so annotate it with data_race()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - nfsd is the in-kernel NFS server; inbound TCP/UDP/RDMA traffic hits svc_tcp_listen_data_ready/svc_data_ready then svc_xprt_enqueue() and svc_pool_for_cpu() before any RPC decode, so a remote peer reaches the bug over the wire.\nAC:L - On NUMA nfsd hosts using pernode/percpu pools with fewer threads than pools, a remote peer can open connections or send datagrams until RSS/softirq lands the listener or shared UDP xprt on an empty pool; the attacker controls that fan-out and no race or layout luck is required.\nPR:N - Enqueue runs in the socket data_ready path on the first TCP connect or UDP datagram to nfsd, before RPC parsing or AUTH_SYS/RPCSEC_GSS, so an unauthenticated network peer needs no local account or capability.\nUI:N - No victim action is required; an already-running NFS server automatically processes inbound connections and packets through the sunrpc transport callbacks.\nS:U - The hang is confined to the host kernel's sunrpc/nfsd threads and sockets and does not cross a VM, IOMMU, or other security-authority boundary.\nC:N - This is a transport-scheduling hang with no memory corruption, out-of-bounds access, or other primitive that could disclose kernel or file data.\nI:N - A transport stuck on a threadless pool is never serviced, so RPC operations are not executed and no kernel or filesystem state is modified.\nA:H - A transport enqueued on a threadless pool stays XPT_BUSY and is never dequeued; aging skips busy sockets, so a stuck listener or shared UDP xprt permanently stops NFS accept/recv until nfsd restarts."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/svc.c"],"versions":[{"version":"bfd241600a3b0db4fe43c859f1460d0a958d924a","lessThan":"9accc25e5af0bac8479f6054e674b2c593c45281","status":"affected","versionType":"git"},{"version":"bfd241600a3b0db4fe43c859f1460d0a958d924a","lessThan":"6f66d38e2a6c78d48723ea17ad86135ec80ca24b","status":"affected","versionType":"git"},{"version":"bfd241600a3b0db4fe43c859f1460d0a958d924a","lessThan":"d79d7b9e8acbb53e2d60f6b24afc13e2f15e691f","status":"affected","versionType":"git"},{"version":"bfd241600a3b0db4fe43c859f1460d0a958d924a","lessThan":"edb20e8c03aebacb409968c99d046f509c6c485a","status":"affected","versionType":"git"},{"version":"bfd241600a3b0db4fe43c859f1460d0a958d924a","lessThan":"011479cf9a7657d4a3e7cc42a784ac63df594170","status":"affected","versionType":"git"},{"version":"bfd241600a3b0db4fe43c859f1460d0a958d924a","lessThan":"9d04d64ad192439835ed9884d767353061c3ed6f","status":"affected","versionType":"git"},{"version":"bfd241600a3b0db4fe43c859f1460d0a958d924a","lessThan":"8f766d2d0b4dabf54f8b35812df2b4f481d13316","status":"affected","versionType":"git"},{"version":"bfd241600a3b0db4fe43c859f1460d0a958d924a","lessThan":"f6310491c4cdb88af73aa551ec9df1f10a90c709","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/svc.c"],"versions":[{"version":"2.6.19","status":"affected"},{"version":"0","lessThan":"2.6.19","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9accc25e5af0bac8479f6054e674b2c593c45281"},{"url":"https://git.kernel.org/stable/c/6f66d38e2a6c78d48723ea17ad86135ec80ca24b"},{"url":"https://git.kernel.org/stable/c/d79d7b9e8acbb53e2d60f6b24afc13e2f15e691f"},{"url":"https://git.kernel.org/stable/c/edb20e8c03aebacb409968c99d046f509c6c485a"},{"url":"https://git.kernel.org/stable/c/011479cf9a7657d4a3e7cc42a784ac63df594170"},{"url":"https://git.kernel.org/stable/c/9d04d64ad192439835ed9884d767353061c3ed6f"},{"url":"https://git.kernel.org/stable/c/8f766d2d0b4dabf54f8b35812df2b4f481d13316"},{"url":"https://git.kernel.org/stable/c/f6310491c4cdb88af73aa551ec9df1f10a90c709"}],"title":"sunrpc: route to a populated pool in svc_pool_for_cpu()","x_generator":{"engine":"bippy-1.2.0"}}}}