CVE-2026-89535
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id<br />
<br />
svc_rdma_free() caches rdma->sc_cm_id->device before teardown,<br />
then calls rdma_destroy_id(sc_cm_id) which frees the cm_id.<br />
rpcrdma_rn_unregister() follows, but between those two calls<br />
the transport&#39;s sc_rn entry is still installed in the device&#39;s<br />
rd_xa. A concurrent ib_unregister_device walk can dispatch<br />
svc_rdma_xprt_done() against the now-freed sc_cm_id.<br />
<br />
Move rpcrdma_rn_unregister() before rdma_destroy_id() so the<br />
transport&#39;s notification entry is removed from the xarray before<br />
the cm_id it references is destroyed.<br />
<br />
Also guard the sc_cm_id dereference with a NULL check: the<br />
following patches introduce paths that reach svc_rdma_free()<br />
with sc_cm_id == NULL (listener create failure, ADDR_CHANGE<br />
replacement failure).
Impacto
Puntuación base 3.x
8.10
Gravedad 3.x
ALTA


