CVE-2026-89527
Received Received - Intake

Memory Leak in Linux Kernel RPC Service

Vulnerability report for CVE-2026-89527, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Use svc_xprt_put to free listener on create failure svc_rdma_create() calls kfree(cma_xprt) when svc_rdma_create_listen_id() fails. svc_xprt_init() has already acquired a net namespace reference via get_net_track(); kfree bypasses svc_xprt_free() which releases it. Replace the kfree() with svc_xprt_put() so the kref_init birth reference drops to zero and svc_xprt_free() dispatches svc_rdma_free() to clean up properly. sc_cm_id is still NULL at that point; the preceding patch added the necessary NULL guard in svc_rdma_free(). svc_xprt_free() also drops the module reference via module_put(), but the caller _svc_xprt_create() does the same on xpo_create failure, double-putting the single try_module_get() it acquired. Take a compensating __module_get() before the svc_xprt_put() to keep the count balanced, matching the convention in svc_rdma_accept()'s error path.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a memory management flaw in the Linux kernel's svcrdma module. When setting up a network service, the code incorrectly frees memory using kfree() instead of the proper svc_xprt_put() function. This bypasses cleanup routines that release critical resources like network namespace references.

Detection Guidance

This vulnerability is specific to the Linux kernel's svcrdma module and may not have direct detection commands. Monitoring kernel logs for errors related to svcrdma or RPC services could indicate issues. Check for kernel panics or memory leaks in svcrdma-related processes.

Impact Analysis

If exploited, this could cause resource leaks leading to system instability or denial of service. Attackers might trigger the error path to exhaust kernel memory or network resources. Systems using NFS over RDMA could be particularly affected.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it is a memory management issue in the Linux kernel's svcrdma module. It involves improper cleanup of network transport resources during failure scenarios, which does not relate to data protection or privacy requirements.

Mitigation Strategies

Update the Linux kernel to the latest patched version. If immediate patching is not possible, disable the svcrdma module by blacklisting it or restricting RPC services using firewall rules until the kernel is updated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89527. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart