Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-89535

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id<br /> <br /> svc_rdma_free() caches rdma-&gt;sc_cm_id-&gt;device before teardown,<br /> then calls rdma_destroy_id(sc_cm_id) which frees the cm_id.<br /> rpcrdma_rn_unregister() follows, but between those two calls<br /> the transport&amp;#39;s sc_rn entry is still installed in the device&amp;#39;s<br /> rd_xa. A concurrent ib_unregister_device walk can dispatch<br /> svc_rdma_xprt_done() against the now-freed sc_cm_id.<br /> <br /> Move rpcrdma_rn_unregister() before rdma_destroy_id() so the<br /> transport&amp;#39;s notification entry is removed from the xarray before<br /> the cm_id it references is destroyed.<br /> <br /> Also guard the sc_cm_id dereference with a NULL check: the<br /> following patches introduce paths that reach svc_rdma_free()<br /> with sc_cm_id == NULL (listener create failure, ADDR_CHANGE<br /> replacement failure).