← All Advisories

CVE-2026-89798

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89798

Key Details

CVECVE-2026-89798
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

rpcrdma: arm rn_done before publishing the notification

rpcrdma_rn_register() inserts @rn into rd_xa with xa_alloc() before

storing the caller's callback in rn->rn_done. The xarray makes @rn

reachable to rpcrdma_remove_one(), which walks rd_xa and invokes

rn->rn_done(rn) for every registered notification. A device removal

that races a fresh registration can therefore observe @rn with

rn_done still NULL, because the notification objects are zero

allocated by their owners, and call through a NULL function pointer.

Store rn->rn_done before xa_alloc() publishes @rn. The xarray's

store-side and load-side ordering then guarantees that any CPU which

finds @rn in rd_xa also observes the armed callback.

rpcrdma_rn_unregister() treats a non-NULL rn_done as the sentinel

for a completed registration, so the early store must not survive a

failed registration. Clear rn_done again when xa_alloc() fails.

Were it left set, the failed-accept cleanup path would call

rpcrdma_rn_unregister() on an @rn that was never inserted, erasing

an unrelated rd_xa slot and underflowing rd_kref. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89798
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89798