CVE-2026-89534
Received Received - Intake

svcrdma Use-After-Free in Linux Kernel

Vulnerability report for CVE-2026-89534, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails When svc_rdma_listen_handler() handles RDMA_CM_EVENT_ADDR_CHANGE, it creates a replacement listener cm_id and returns 1, telling the CM core to destroy the old one. If the replacement allocation fails, sc_cm_id still points at the old cm_id that the CM core is about to destroy. Any subsequent dereference of sc_cm_id -- such as svc_rdma_detach()'s rdma_disconnect() call -- is a use-after-free. NULL sc_cm_id on the failure path and guard svc_rdma_detach()'s rdma_disconnect() call against NULL so that the listener can be torn down safely when the server shuts down.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in the Linux kernel's svcrdma module. When handling an RDMA_CM_EVENT_ADDR_CHANGE event, if replacement listener allocation fails, the old cm_id pointer is not cleared. This can lead to a use-after-free when the old cm_id is later dereferenced during server shutdown.

Detection Guidance

This vulnerability is specific to the Linux kernel's svcrdma module and requires kernel-level inspection. Detection involves checking kernel logs for svcrdma-related errors or crashes, particularly during RDMA_CM_EVENT_ADDR_CHANGE events. Use commands like dmesg | grep svcrdma or journalctl -k | grep svcrdma to review kernel logs for anomalies.

Impact Analysis

This vulnerability could allow an attacker to cause a denial of service or potentially execute arbitrary code with kernel privileges by triggering the use-after-free condition. Systems using RDMA services may be affected.

Compliance Impact

This vulnerability is a use-after-free issue in the Linux kernel's svcrdma module that could lead to memory corruption or crashes. It does not directly affect compliance with standards like GDPR or HIPAA, as those focus on data protection, privacy, and security controls rather than kernel memory management flaws.

Mitigation Strategies

Immediately update the Linux kernel to a patched version that includes the fix for CVE-2026-89534. If immediate patching is not possible, disable the svcrdma module by unloading the rdma_svc kernel module (rmmod rdma_svc) as a temporary workaround. Ensure RDMA services are not running during this process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89534. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart