CVE-2026-89545

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> sunrpc: defer rq_argp and rq_resp free until after RCU grace period<br /> <br /> svc_rqst_free() frees rqstp-&gt;rq_argp and rqstp-&gt;rq_resp synchronously<br /> via kfree(), but defers the rqstp struct free via kfree_rcu(). After<br /> svc_exit_thread() calls list_del_rcu() and svc_rqst_free(), there is<br /> a window where RCU readers that started before list_del_rcu() can still<br /> traverse the thread list and find the rqstp. These readers (e.g.<br /> nfsd_nl_rpc_status_get_dumpit()) dereference rqstp-&gt;rq_argp, which has<br /> already been freed — a use-after-free.<br /> <br /> Fix this by moving the kfree of rq_argp and rq_resp into an explicit<br /> call_rcu() callback alongside the struct free. Resources not accessed<br /> by RCU readers (bvec, buffer pages, scratch folio, auth_data) remain<br /> synchronously freed.