CVE-2026-89549
Received Received - Intake

Linux Kernel SunRPC Thread Pool Routing Flaw

Vulnerability report for CVE-2026-89549, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: sunrpc: route to a populated pool in svc_pool_for_cpu() svc_set_num_threads() spreads the requested threads evenly across the service's pools (base = nrservs / sv_nrpools). When a service runs fewer threads than it has pools -- e.g. an nfsd configured with fewer threads than the host has NUMA nodes while running in "pernode" or "percpu" mode -- the trailing pools are left with no threads at all. svc_xprt_enqueue() selects a pool from the CPU servicing the transport, queues the transport on that pool's sp_xprts, and only wakes a thread from the same pool. Each thread services exclusively its own pool, so a transport that lands on a threadless pool is enqueued on sp_xprts and never picked up: the connection hangs indefinitely. Have svc_pool_for_cpu() skip pools that currently have no threads, falling back to the next populated pool. This trades NUMA locality for a guarantee that the work is actually serviced. sp_nrthreads is only updated under the service mutex; the lockless read here is a best-effort routing hint, so annotate it with data_race().

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel affects the SunRPC service. When a service like NFS is configured with fewer threads than the host has NUMA nodes, some pools of threads may remain empty. Connections are routed to these empty pools and hang indefinitely because no threads are available to service them.

Detection Guidance

This vulnerability affects the Linux kernel's sunrpc service, specifically when NFS services are configured with fewer threads than NUMA nodes in pernode or percpu mode. Detection involves checking NFS server thread allocation and pool distribution. Examine /proc/fs/nfsd/threads and /proc/fs/nfsd/pool_stats for thread counts per pool. Look for pools with zero threads while others are overloaded. Monitor hanging NFS connections or timeouts during high load.

Impact Analysis

If you use NFS or other SunRPC-based services on a Linux system with multiple NUMA nodes, this vulnerability could cause network connections to hang or time out. Services may become unresponsive, leading to disruptions in file sharing or remote procedure calls.

Mitigation Strategies

Upgrade the Linux kernel to a patched version that includes the fix for this issue. If upgrading is not immediately possible, adjust NFS server configuration to ensure the number of threads matches or exceeds the number of NUMA nodes. Avoid pernode or percpu modes if running with fewer threads. Monitor NFS performance and connection stability after changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89549. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart