← All Advisories

CVE-2026-89535

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89535

Key Details

CVECVE-2026-89535
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id

svc_rdma_free() caches rdma->sc_cm_id->device before teardown,

then calls rdma_destroy_id(sc_cm_id) which frees the cm_id.

rpcrdma_rn_unregister() follows, but between those two calls

the transport's sc_rn entry is still installed in the device's

rd_xa. A concurrent ib_unregister_device walk can dispatch

svc_rdma_xprt_done() against the now-freed sc_cm_id.

Move rpcrdma_rn_unregister() before rdma_destroy_id() so the

transport's notification entry is removed from the xarray before

the cm_id it references is destroyed.

Also guard the sc_cm_id dereference with a NULL check: the

following patches introduce paths that reach svc_rdma_free()

with sc_cm_id == NULL (listener create failure, ADDR_CHANGE

replacement failure). (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89535
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89535