rpcrdma: arm rn_done before publishing the notification
Summary
| CVE | CVE-2026-89798 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 11:16:44 UTC |
| Updated | 2026-09-21 14:17:26 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: rpcrdma: arm rn_done before publishing the notification rpcrdma_rn_register() inserts @rn into rd_xa with xa_alloc() before storing the caller's callback in rn->rn_done. The xarray makes @rn reachable to rpcrdma_remove_one(), which walks rd_xa and invokes rn->rn_done(rn) for every registered notification. A device removal that races a fresh registration can therefore observe @rn with rn_done still NULL, because the notification objects are zero allocated by their owners, and call through a NULL function pointer. Store rn->rn_done before xa_alloc() publishes @rn. The xarray's store-side and load-side ordering then guarantees that any CPU which finds @rn in rd_xa also observes the armed callback. rpcrdma_rn_unregister() treats a non-NULL rn_done as the sentinel for a completed registration, so the early store must not survive a failed registration. Clear rn_done again when xa_alloc() fails. Were it left set, the failed-accept cleanup path would call rpcrdma_rn_unregister() on an @rn that was never inserted, erasing an unrelated rd_xa slot and underflowing rd_kref. |
Risk And Classification
EPSS: 0.002000000 probability, percentile 0.101220000 (date 2026-09-22)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 7e86845a0346efc95fddaa97ce5cd6a8bda8c71c f9fe3cad43c42d874a388583552b39b411d886eb git | Not specified |
| CNA | Linux | Linux | affected 7e86845a0346efc95fddaa97ce5cd6a8bda8c71c 3c97b8e76ca2bba9e8770571413aed694068e78e git | Not specified |
| CNA | Linux | Linux | affected 7e86845a0346efc95fddaa97ce5cd6a8bda8c71c ea0408273ccf5df1fb52d9a1b9db4d31600dcb36 git | Not specified |
| CNA | Linux | Linux | affected 7e86845a0346efc95fddaa97ce5cd6a8bda8c71c 5b06f706374c37375bdff9d21cc10e61df925a92 git | Not specified |
| CNA | Linux | Linux | affected 6.11 | Not specified |
| CNA | Linux | Linux | unaffected 6.11 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.111 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.51 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.5 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/ea0408273ccf5df1fb52d9a1b9db4d31600dcb36 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/5b06f706374c37375bdff9d21cc10e61df925a92 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f9fe3cad43c42d874a388583552b39b411d886eb | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/3c97b8e76ca2bba9e8770571413aed694068e78e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.