-

CVE-2026-89798

rpcrdma: arm rn_done before publishing the notification

In the Linux kernel, the following vulnerability has been resolved:

rpcrdma: arm rn_done before publishing the notification

rpcrdma_rn_register() inserts @rn into rd_xa with xa_alloc() before
storing the caller's callback in rn->rn_done. The xarray makes @rn
reachable to rpcrdma_remove_one(), which walks rd_xa and invokes
rn->rn_done(rn) for every registered notification. A device removal
that races a fresh registration can therefore observe @rn with
rn_done still NULL, because the notification objects are zero
allocated by their owners, and call through a NULL function pointer.

Store rn->rn_done before xa_alloc() publishes @rn. The xarray's
store-side and load-side ordering then guarantees that any CPU which
finds @rn in rd_xa also observes the armed callback.

rpcrdma_rn_unregister() treats a non-NULL rn_done as the sentinel
for a completed registration, so the early store must not survive a
failed registration. Clear rn_done again when xa_alloc() fails.
Were it left set, the failed-accept cleanup path would call
rpcrdma_rn_unregister() on an @rn that was never inserted, erasing
an unrelated rd_xa slot and underflowing rd_kref.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7e86845a0346efc95fddaa97ce5cd6a8bda8c71c
Version < f9fe3cad43c42d874a388583552b39b411d886eb
Status affected
Version 7e86845a0346efc95fddaa97ce5cd6a8bda8c71c
Version < 3c97b8e76ca2bba9e8770571413aed694068e78e
Status affected
Version 7e86845a0346efc95fddaa97ce5cd6a8bda8c71c
Version < ea0408273ccf5df1fb52d9a1b9db4d31600dcb36
Status affected
Version 7e86845a0346efc95fddaa97ce5cd6a8bda8c71c
Version < 5b06f706374c37375bdff9d21cc10e61df925a92
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3c97b8e76ca2bba9e8770571413aed694068e78e
https://git.kernel.org/stable/c/ea0408273ccf5df1fb52d9a1b9db4d31600dcb36
https://git.kernel.org/stable/c/5b06f706374c37375bdff9d21cc10e61df925a92
https://git.kernel.org/stable/c/f9fe3cad43c42d874a388583552b39b411d886eb