8.1

CVE-2026-89535

svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id

svc_rdma_free() caches rdma->sc_cm_id->device before teardown,
then calls rdma_destroy_id(sc_cm_id) which frees the cm_id.
rpcrdma_rn_unregister() follows, but between those two calls
the transport's sc_rn entry is still installed in the device's
rd_xa. A concurrent ib_unregister_device walk can dispatch
svc_rdma_xprt_done() against the now-freed sc_cm_id.

Move rpcrdma_rn_unregister() before rdma_destroy_id() so the
transport's notification entry is removed from the xarray before
the cm_id it references is destroyed.

Also guard the sc_cm_id dereference with a NULL check: the
following patches introduce paths that reach svc_rdma_free()
with sc_cm_id == NULL (listener create failure, ADDR_CHANGE
replacement failure).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version c4de97f7c45434985e5dbf2d6ccc9eca676e37fe
Version < fcd4a752ac840d39356f4d2a424d3aca4e39716b
Status affected
Version c4de97f7c45434985e5dbf2d6ccc9eca676e37fe
Version < 9f2f5d0999364c7070306cd422d8babc2621070d
Status affected
Version c4de97f7c45434985e5dbf2d6ccc9eca676e37fe
Version < cfca6eb3345ba4a23cf9a1153ad09bf19faabfc9
Status affected
Version c4de97f7c45434985e5dbf2d6ccc9eca676e37fe
Version < 4488e912973773d64368828acf3b8e39d93650ae
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.12
Status affected
Version 0
Version < 6.12
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.421
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9f2f5d0999364c7070306cd422d8babc2621070d
https://git.kernel.org/stable/c/cfca6eb3345ba4a23cf9a1153ad09bf19faabfc9
https://git.kernel.org/stable/c/4488e912973773d64368828acf3b8e39d93650ae
https://git.kernel.org/stable/c/fcd4a752ac840d39356f4d2a424d3aca4e39716b