* CVE-2026-89527: svcrdma: Use svc_xprt_put to free listener on create failure
@ 2026-09-11 19:43 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:43 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
svcrdma: Use svc_xprt_put to free listener on create failure
svc_rdma_create() calls kfree(cma_xprt) when
svc_rdma_create_listen_id() fails. svc_xprt_init() has already
acquired a net namespace reference via get_net_track(); kfree
bypasses svc_xprt_free() which releases it.
Replace the kfree() with svc_xprt_put() so the kref_init birth
reference drops to zero and svc_xprt_free() dispatches
svc_rdma_free() to clean up properly. sc_cm_id is still NULL
at that point; the preceding patch added the necessary NULL
guard in svc_rdma_free().
svc_xprt_free() also drops the module reference via
module_put(), but the caller _svc_xprt_create() does the same
on xpo_create failure, double-putting the single
try_module_get() it acquired. Take a compensating
__module_get() before the svc_xprt_put() to keep the count
balanced, matching the convention in svc_rdma_accept()'s error
path.
The Linux kernel CVE team has assigned CVE-2026-89527 to this issue.
Affected and fixed versions
===========================
Issue introduced in 2.6.37 with commit 4fb8518bdac8e85f6580ea3f586adf396cd472bc and fixed in 7.2.4 with commit ac1dd6002f758ab7dd3e737757e5a1bb1c0b38d6
Issue introduced in 2.6.37 with commit 4fb8518bdac8e85f6580ea3f586adf396cd472bc and fixed in 7.3-rc1 with commit e346ef7bcb137f50c49f969330ab7dcf64ea1654
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-89527
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
net/sunrpc/xprtrdma/svc_rdma_transport.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/ac1dd6002f758ab7dd3e737757e5a1bb1c0b38d6
https://git.kernel.org/stable/c/e346ef7bcb137f50c49f969330ab7dcf64ea1654
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-11 19:54 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:43 CVE-2026-89527: svcrdma: Use svc_xprt_put to free listener on create failure Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.