CVE-2026-89536
Received Received - Intake

Linux Kernel SUNRPC TLS Handshake Race Condition

Vulnerability report for CVE-2026-89536, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: wait for in-flight client TLS handshake callback xs_tls_handshake_sync() gives xs_tls_handshake_done() a reference to the lower transport before submitting the handshake request. On timeout or signal, the synchronous waiter drops that reference after calling tls_handshake_cancel(). handshake_req_cancel() returns false when handshake_complete() has already marked the request complete. In that case the completion callback can still be running, so dropping the callback-owned reference in the waiter can free the lower transport before xs_tls_handshake_done() stores xprt_err or drops its own reference. If cancellation loses to completion, wait until xs_tls_handshake_done() signals handshake_done and let the callback release its reference. This mirrors the server-side handshake lifetime handling and keeps the timeout or signal return value unchanged.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a race condition in the SUNRPC subsystem during TLS handshake processing. When a client TLS handshake is canceled due to timeout or signal, the system may incorrectly drop a reference to the lower transport layer before the handshake completion callback finishes, potentially leading to use-after-free or memory corruption.

Detection Guidance

This vulnerability is specific to the Linux kernel's SUNRPC TLS handshake handling. Detection requires checking kernel logs for RPC over TLS handshake timeouts or errors. Monitor logs for messages related to xs_tls_handshake_sync or handshake cancellation. Use commands like dmesg | grep -i 'tls_handshake' or journalctl -k | grep -i 'rpc' to inspect kernel logs for related errors.

Impact Analysis

This could cause system instability, crashes, or privilege escalation if exploited. Systems relying on RPC over TLS for secure communication may experience denial-of-service or data corruption.

Compliance Impact

This vulnerability in the Linux kernel's SUNRPC TLS handshake mechanism could potentially impact compliance with data protection regulations like GDPR or HIPAA by creating conditions where secure data transmission might be interrupted or improperly handled during TLS handshake cancellations. However, the provided CVE details do not explicitly describe compliance implications.

Mitigation Strategies

Apply the latest Linux kernel security updates to patch this issue. If immediate patching is not possible, consider disabling RPC over TLS (if feasible) or restricting RPC services to trusted networks until the update is applied. Monitor vendor advisories for kernel updates addressing this CVE.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89536. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart