SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89535

HIGH · CVSS 8.1 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's svcrdma component, where improper ordering of function calls can lead to a use-after-free condition. This flaw allows a concurrent process to access a freed memory reference, potentially leading to system instability or exploitation. Organizations utilizing Linux systems with svcrdma should prioritize addressing this issue to mitigate risks associated with potential denial-of-service attacks or unauthorized access.

CVE
CVE-2026-89535
Severity
HIGH
CVSS
8.1
EPSS
0.51%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id svc_rdma_free() caches rdma->sc_cm_id->device before teardown, then calls rdma_destroy_id(sc_cm_id) which frees the cm_id. rpcrdma_rn_unregister() follows, but between those two calls the transport's sc_rn entry is still installed in the device's rd_xa. A concurrent ib_unregister_device walk can dispatch svc_rdma_xprt_done() against the now-freed sc_cm_id. Move rpcrdma_rn_unregister() before rdma_destroy_id() so the transport's notification entry is removed from the xarray before the cm_id it references is destroyed. Also guard the sc_cm_id dereference with a NULL check: the following patches introduce paths that reach svc_rdma_free() with sc_cm_id == NULL (listener create failure, ADDR_CHANGE replacement failure).