Description
In the Linux kernel, the following vulnerability has been resolved:

ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()

Commit 9e91f8a6c868 ("ipmi:msghandler: Remove srcu for the
ipmi_interfaces list") dropped the synchronize_rcu() between unlinking
the command receivers from intf->cmd_rcvrs and freeing them, updating
only the comment that explains why the barrier is needed.

The cmd_rcvrs list is still traversed under plain RCU: find_cmd_rcvr()
walks it inside rcu_read_lock(), and handle_ipmb_get_msg_cmd() borrows
rcvr->user from that lookup within the same read-side section. Without
the grace period, _ipmi_destroy_user() can kfree() a cmd_rcvr while a
reader still holds a pointer to it, causing a use-after-free.

The rework only made srcu unnecessary for the interfaces list; the
cmd_rcvrs list still relies on plain RCU. Restore the synchronize_rcu()
before freeing the receivers.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After‑Free leading to kernel memory corruption
Action: Patch kernel
AI Analysis

Impact

In the Linux kernel IPMI subsystem, a use‑after‑free bug occurs when the command‑receiver structure is freed while a reader still holds a reference to it. This race originates from the removal of the synchronize_rcu() barrier that previously separated the unlinking of command receivers from their deallocation, leaving the list traversed under plain RCU. The resulting memory corruption can compromise kernel memory integrity and may trigger a crash or unexpected behavior. The flaw is classified as CWE‑825, indicating a race condition that can lead to a use‑after‑free vulnerability. While the description does not explicitly state arbitrary code execution, the kernel memory corruption could potentially be leveraged to elevate privileges if an attacker can influence the dereferenced data.

Affected Systems

The affected product is the generic Linux kernel build that includes the legacy IPMI interface code without the commit restoring the synchronize_rcu() barrier. No specific vendor or product variants are listed, and affected kernel versions are not enumerated, so any kernel containing the vulnerable code should be considered at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, while the EPSS score of <1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to have the ability to send IPMI commands to the target’s BMC to trigger the flaw. If such access is achieved, the memory corruption could enable the attacker to interfere with kernel execution paths or elevate privileges.

Generated by OpenCVE AI on September 15, 2026 at 22:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commit restoring the synchronize_rcu() barrier before freeing command receivers.
  • If the IPMI subsystem is not required, unload or disable the relevant IPMI kernel modules (e.g., ipmi_kcs, ipmi_msghandler) to eliminate the attack surface.
  • Restrict IPMI/BMC remote access to trusted interfaces or networks, or secure BMC credentials to prevent unauthorized command injection.

Generated by OpenCVE AI on September 15, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user() Commit 9e91f8a6c868 ("ipmi:msghandler: Remove srcu for the ipmi_interfaces list") dropped the synchronize_rcu() between unlinking the command receivers from intf->cmd_rcvrs and freeing them, updating only the comment that explains why the barrier is needed. The cmd_rcvrs list is still traversed under plain RCU: find_cmd_rcvr() walks it inside rcu_read_lock(), and handle_ipmb_get_msg_cmd() borrows rcvr->user from that lookup within the same read-side section. Without the grace period, _ipmi_destroy_user() can kfree() a cmd_rcvr while a reader still holds a pointer to it, causing a use-after-free. The rework only made srcu unnecessary for the interfaces list; the cmd_rcvrs list still relies on plain RCU. Restore the synchronize_rcu() before freeing the receivers.
Title ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:29:55.269Z

Reserved: 2026-09-11T19:38:34.712Z

Link: CVE-2026-89486

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:30.297

Modified: 2026-09-13T07:17:11.900

Link: CVE-2026-89486

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:40Z

Links: CVE-2026-89486 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:45:07Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference