Description
In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Use svc_xprt_put to free listener on create failure

svc_rdma_create() calls kfree(cma_xprt) when
svc_rdma_create_listen_id() fails. svc_xprt_init() has already
acquired a net namespace reference via get_net_track(); kfree
bypasses svc_xprt_free() which releases it.

Replace the kfree() with svc_xprt_put() so the kref_init birth
reference drops to zero and svc_xprt_free() dispatches
svc_rdma_free() to clean up properly. sc_cm_id is still NULL
at that point; the preceding patch added the necessary NULL
guard in svc_rdma_free().

svc_xprt_free() also drops the module reference via
module_put(), but the caller _svc_xprt_create() does the same
on xpo_create failure, double-putting the single
try_module_get() it acquired. Take a compensating
__module_get() before the svc_xprt_put() to keep the count
balanced, matching the convention in svc_rdma_accept()'s error
path.
Published: 2026-09-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Instability
Action: Patch
AI Analysis

Impact

A flaw in the Linux kernel’s remote‑direct memory access (rdma) listener creation path causes a reference counter imbalance; the code path bypasses the normal cleanup routine and frees memory directly. This can leave the network namespace and module reference counts unbalanced, leading to a memory leak and, if the imbalance occurs frequently, to a kernel crash or other instability. The weakness is classified as CWE‑772, a reference count error. The vulnerability itself does not disclose data or allow code execution, but it jeopardizes the reliability of the kernel.

Affected Systems

All Linux kernel distributions that include the svcrdma module before the vendor’s patch are affected. The vulnerability is present in any kernel that ships with the unpatched svcrdma code, regardless of specific release version, as the affected code exists before the recent commit that applies the fix.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate risk level. Because the EPSS score is less than 1 % the probability of exploitation is inferred to be low, but the vulnerability is not cataloged in CISA’s known exploited vulnerabilities list. Exploitation would require a local attacker with kernel/module load privileges to force the listener‑creation failure path, typically by providing malformed input or triggering module load errors. The consequence is resource exhaustion or a potential kernel panic, impacting availability but not confidentiality or integrity.

Generated by OpenCVE AI on September 15, 2026 at 22:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the svcrdma patch replacing the kfree call with svc_xprt_put and adding a compensating module_get.
  • If an immediate kernel update cannot be performed, unload or disable the svcrdma module or related configuration options to remove the vulnerable code from the system.
  • Continuously monitor kernel logs (dmesg and /var/log/kern.log) for messages indicating svcrdma failures or reference count anomalies to detect any potential instability.

Generated by OpenCVE AI on September 15, 2026 at 22:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: svcrdma: Use svc_xprt_put to free listener on create failure svc_rdma_create() calls kfree(cma_xprt) when svc_rdma_create_listen_id() fails. svc_xprt_init() has already acquired a net namespace reference via get_net_track(); kfree bypasses svc_xprt_free() which releases it. Replace the kfree() with svc_xprt_put() so the kref_init birth reference drops to zero and svc_xprt_free() dispatches svc_rdma_free() to clean up properly. sc_cm_id is still NULL at that point; the preceding patch added the necessary NULL guard in svc_rdma_free(). svc_xprt_free() also drops the module reference via module_put(), but the caller _svc_xprt_create() does the same on xpo_create failure, double-putting the single try_module_get() it acquired. Take a compensating __module_get() before the svc_xprt_put() to keep the count balanced, matching the convention in svc_rdma_accept()'s error path.
Title svcrdma: Use svc_xprt_put to free listener on create failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:44:07.785Z

Reserved: 2026-09-11T19:38:34.719Z

Link: CVE-2026-89527

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:35.503

Modified: 2026-09-11T20:19:35.503

Link: CVE-2026-89527

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:07Z

Links: CVE-2026-89527 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:30:15Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime