From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EB4D5581259 for ; Fri, 11 Sep 2026 19:52:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156354; cv=none; b=PICi4D60Lx64wV55sJcUOVBkGoQ1yRYUElRwW5+0lFPpSQKWtW3r6YKS0N7pMzMmnTlXuWDlFi9xP7TJMXFh5vrGSx+dBNXzWZkMn09H3mHFrLXPn9V//OmgB/Qn/9bmEyHv0LlFLKTMYQHjAAsf6zcGb+G0qpuf3PkHoKaEWOQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156354; c=relaxed/simple; bh=3IGVAdD/KJ9QFwxn1fo2ZdVKzF9gVzDT0H1g156GF78=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=HYCqZ/p2CzriwFwxfYbHNGM8mglWyDX3B+rHWKNHxp24kQDw9ynlbiMxtxz8jUkcfRku8vuOnNh+kWDzBCSnkxzp1guzpRExIrK7bHkr/84Wdm0IIlK4tmvDLznXJ8HbVtf2ryk+IEVK8FrVEm8bPTISrhlP0tvOU/kq/o1DtK8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=bsz4QQl/; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="bsz4QQl/" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5295A1F00893; Fri, 11 Sep 2026 19:52:22 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156342; bh=IgGfSDwxA6ut2WYKW9HtmRXMBaTmOjWj4ipaaXF6fuM=; h=From:To:Cc:Subject:Date:Reply-To; b=bsz4QQl/bDObiiI6JuekDzpTuxeJ6PAZoz05mtiD9lkntxug3QmqmEJGiZ8LMGzrr SA3832k9PkOub0yRBpY/EgdtmDuYFk1rS00vauF8adHNKZFT+G/Q8qJcx8OmJu2SRo qJOYTHf65OetFmD6p1uIjnNKZrd28f3vXDpjuQM0= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89486: ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user() Date: Fri, 11 Sep 2026 21:42:55 +0200 Message-ID: <2026091106-CVE-2026-89486-346c@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2796; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=NkztRgLLfJk351oAH7oi+EE6naux+MMSxSQCyYaSlKI=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIoMadyzMkz+dMCNXcHuk1O95q2f43pNWnXxa7u3+d 6slbhsXdsSyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBEIuMZFhz5Usoyo+Nr5eaD fm7qKyoKe6qW1TLM99mzfLGLSD6LsN8ZI5ff7i9Y+z6YAQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user() Commit 9e91f8a6c868 ("ipmi:msghandler: Remove srcu for the ipmi_interfaces list") dropped the synchronize_rcu() between unlinking the command receivers from intf->cmd_rcvrs and freeing them, updating only the comment that explains why the barrier is needed. The cmd_rcvrs list is still traversed under plain RCU: find_cmd_rcvr() walks it inside rcu_read_lock(), and handle_ipmb_get_msg_cmd() borrows rcvr->user from that lookup within the same read-side section. Without the grace period, _ipmi_destroy_user() can kfree() a cmd_rcvr while a reader still holds a pointer to it, causing a use-after-free. The rework only made srcu unnecessary for the interfaces list; the cmd_rcvrs list still relies on plain RCU. Restore the synchronize_rcu() before freeing the receivers. The Linux kernel CVE team has assigned CVE-2026-89486 to this issue. Affected and fixed versions =========================== Issue introduced in 6.16 with commit 9e91f8a6c8688e27f4ccce7db457da87d6458836 and fixed in 6.18.50 with commit 3088e41292fecf132f85f79af5ee4d620b9ff1b4 Issue introduced in 6.16 with commit 9e91f8a6c8688e27f4ccce7db457da87d6458836 and fixed in 7.2.4 with commit 5dc0b2a9af95a97861c1bffaf1687a3173e395c5 Issue introduced in 6.16 with commit 9e91f8a6c8688e27f4ccce7db457da87d6458836 and fixed in 7.3-rc1 with commit 05ec76cfbce653e07cec19b9b8b20e33449d5d87 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89486 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/char/ipmi/ipmi_msghandler.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/3088e41292fecf132f85f79af5ee4d620b9ff1b4 https://git.kernel.org/stable/c/5dc0b2a9af95a97861c1bffaf1687a3173e395c5 https://git.kernel.org/stable/c/05ec76cfbce653e07cec19b9b8b20e33449d5d87