← All Advisories

CVE-2026-89543

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89543

Key Details

CVECVE-2026-89543
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir

Normal client creation goes through rpc_setup_pipedir(), which records

clnt->pipefs_sb, but the mount-event path in __rpc_clnt_handle_event()

calls rpc_setup_pipedir_sb() directly and never refreshes that field.

The umount path also removes the directory without clearing

clnt->pipefs_sb.

After a late pipefs mount or any remount, rpc_clnt_remove_pipedir()

compares the current superblock against a stale pipefs_sb pointer and

skips cleanup, leaving pipefs dentries whose inode private data still

points at a freed rpc_clnt, leading to a potential use-after-free during

subsequent rpc_info_open() or rpc_show_info() calls.

Fix this by properly updating clnt->pipefs_sb upon mount events and

clearing it during unmount or failure paths. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89543
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89543