Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-89543

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir<br /> <br /> Normal client creation goes through rpc_setup_pipedir(), which records<br /> clnt-&gt;pipefs_sb, but the mount-event path in __rpc_clnt_handle_event()<br /> calls rpc_setup_pipedir_sb() directly and never refreshes that field.<br /> The umount path also removes the directory without clearing<br /> clnt-&gt;pipefs_sb.<br /> <br /> After a late pipefs mount or any remount, rpc_clnt_remove_pipedir()<br /> compares the current superblock against a stale pipefs_sb pointer and<br /> skips cleanup, leaving pipefs dentries whose inode private data still<br /> points at a freed rpc_clnt, leading to a potential use-after-free during<br /> subsequent rpc_info_open() or rpc_show_info() calls.<br /> <br /> Fix this by properly updating clnt-&gt;pipefs_sb upon mount events and<br /> clearing it during unmount or failure paths.

Impacto