-

CVE-2026-89543

sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir

Normal client creation goes through rpc_setup_pipedir(), which records
clnt->pipefs_sb, but the mount-event path in __rpc_clnt_handle_event()
calls rpc_setup_pipedir_sb() directly and never refreshes that field.
The umount path also removes the directory without clearing
clnt->pipefs_sb.

After a late pipefs mount or any remount, rpc_clnt_remove_pipedir()
compares the current superblock against a stale pipefs_sb pointer and
skips cleanup, leaving pipefs dentries whose inode private data still
points at a freed rpc_clnt, leading to a potential use-after-free during
subsequent rpc_info_open() or rpc_show_info() calls.

Fix this by properly updating clnt->pipefs_sb upon mount events and
clearing it during unmount or failure paths.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version bfca5fb4e97c46503ddfc582335917b0cc228264
Version < 59527bbfb1eabdb28e95e7c725886cc2c2899cb3
Status affected
Version bfca5fb4e97c46503ddfc582335917b0cc228264
Version < e769fcde3cc73e847b1eb3acd40c04a291cb0c0c
Status affected
Version bfca5fb4e97c46503ddfc582335917b0cc228264
Version < cdf7a233cb94774b0e7df42d9157077983f5022c
Status affected
Version bfca5fb4e97c46503ddfc582335917b0cc228264
Version < 932a8cf6abb2b2f8677b79153a823108d8861fe2
Status affected
Version 17866066b8ac1cc38fb449670bc15dc9fee4b40a
Status affected
Version 7d61d1da2ed1f682c41cae0c8d4719cdaccee5c5
Status affected
Version dedf2a0eb9448ae73b270743e6ea9b108189df46
Status affected
Version 194454afa6aa9d6ed74f0c57127bc8beb27c20df
Status affected
Version 7749fd2dbef72a52b5c9ffdbf877691950ed4680
Status affected
Version 1cdb52ffd6600a37bd355d8dce58ecd03e55e618
Status affected
Version cc2e7ebbeb1d0601f7f3c8d93b78fcc03a95e44a
Status affected
Version 4.19.318
Version < 4.20
Status affected
Version 5.4.280
Version < 5.5
Status affected
Version 5.10.202
Version < 5.11
Status affected
Version 5.15.140
Version < 5.16
Status affected
Version 6.1.64
Version < 6.2
Status affected
Version 6.5.13
Version < 6.6
Status affected
Version 6.6.3
Version < 6.7
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.097
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e769fcde3cc73e847b1eb3acd40c04a291cb0c0c
https://git.kernel.org/stable/c/cdf7a233cb94774b0e7df42d9157077983f5022c
https://git.kernel.org/stable/c/932a8cf6abb2b2f8677b79153a823108d8861fe2
https://git.kernel.org/stable/c/59527bbfb1eabdb28e95e7c725886cc2c2899cb3