CVE-2026-89547
Received Received - Intake

NULL Pointer Dereference in Linux Kernel SUNRPC Service

Vulnerability report for CVE-2026-89547, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Check svc pool percpu counter allocation __svc_create() initializes three per-pool percpu_counter stats and ignores every return value. On SMP, percpu_counter_init() fails when __alloc_percpu_gfp() cannot satisfy the allocation, leaving the failed counter with fbc->counters == NULL and its embedded raw_spinlock_t, list_head, and count never initialized. __svc_create() returns the half-constructed svc_serv to nfsd, lockd, or the NFS callback service anyway. Once that service is live, the hot-path increments in svc_xprt_enqueue(), svc_handle_xprt(), and svc_pool_wake_idle_thread() reach a counter whose backing pointer is NULL. The pointer is a per-cpu offset, so the access does not fault: it resolves to offset zero of the current CPU's per-cpu area and silently corrupts whatever variable lives there. A /proc/fs/nfsd/pool_stats read walks the same NULL per-cpu storage and returns garbage, and on CONFIG_DEBUG_SPINLOCK or lockdep it splats on the never-initialized lock. Creating the broken service requires a percpu allocation failure during RPC server startup, so it is reachable only by a local administrator under memory pressure or fault injection; a remote peer cannot induce the bad state on its own. Check each percpu_counter_init() return value in __svc_create() and fail when an allocation fails, unwinding the counters already set up in the current pool and in every pool initialized before it. A discrete percpu_counter_destroy() per counter at teardown frees each per-cpu allocation exactly once.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel occurs when the SUNRPC subsystem fails to properly initialize per-cpu counters during RPC server startup. The issue arises when memory allocation for these counters fails, but the system continues to use the partially initialized service. This leads to silent memory corruption as the system writes to uninitialized memory locations.

Detection Guidance

This vulnerability is only reachable by a local administrator under memory pressure or fault injection, so detection requires checking kernel logs for RPC server startup failures or per-cpu allocation errors. Monitor /var/log/messages or dmesg for errors during RPC service initialization.

Impact Analysis

This vulnerability can impact you if you are running a Linux system with RPC services like NFS or lockd. A local attacker with administrative privileges could exploit memory pressure or fault injection to trigger the issue, causing silent data corruption or system instability. It may also lead to incorrect statistics being reported via /proc/fs/nfsd/pool_stats.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards. It is a local privilege escalation issue in the Linux kernel's RPC server that could lead to memory corruption under specific conditions. Compliance risks would only arise if this vulnerability were exploited to gain unauthorized access to sensitive data, but no evidence suggests such an impact.

Mitigation Strategies

Apply the Linux kernel patch that checks return values of percpu_counter_init() in __svc_create(). Ensure your system is updated to a kernel version containing this fix. No immediate workaround is needed beyond patching, as the issue requires local access to trigger.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89547. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart