Description
In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Reject connection when transport allocation fails

handle_connect_req() returns without action when
svc_rdma_create_xprt() fails to allocate the new transport.
The CM core returns 0 for CONNECT_REQUEST events, so it does
not destroy the new rdma_cm_id. Each allocation failure under
memory pressure leaks one rdma_cm_id, and a remote peer driving
connection attempts can amplify this.

Reject the connection by returning a non-zero status from the
CM event handler, which tells the CM core to destroy the
orphaned cm_id.
Published: 2026-09-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

In the Linux kernel’s svcrdma module, a failure to allocate a new transport for an RDMA connection causes the connection request handler to return without releasing the allocated rdma_cm_id. Each failed allocation leaks one rdma_cm_id, which can accumulate under memory pressure of service. The weakness is an improper cleanup that results in a resource leak and is categorized as CWE-772. The CVSS score of 5.9 reflects moderate severity.

Affected Systems

The flaw is present in the Linux kernel’s svcrdma module, affecting any kernel release that includes this module and has RDMA enabled. The affected product is the Linux kernel; no specific version ranges are supplied in the current data, so all kernel versions prior to the patch are potentially vulnerable.

Risk and Exploitability

Based on the description, it is inferred that a remote RDMA client can repeatedly issue CONNECT_REQUEST events, gradually leaking rdma_cm_id objects. The flaw does not require elevated privileges; a remote RDMA client can trigger it by repeatedly initiating connection attempts. The CVSS score of 5.9 reflects moderate severity. The EPSS score of < 1% indicates a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The moderate CVSS score and low exploitation probability combine to make this a low‑to moderate‑risk vulnerability that could, however, degrade availability in sustained attack scenarios.

Generated by OpenCVE AI on September 15, 2026 at 06:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel patch that eliminates the resource leak and ensures the CM core destroys orphaned rdma_cm_id objects by returning a non‑zero status.
  • If a patch traffic to trusted hosts by configuring firewall or NIC ACL rules to restrict the number of connection attempts from untrusted peers.
  • Monitor kernel memory usage and track rdma_cm_id counts to investigate any sustained increase as a possible exploitation indicator.

Generated by OpenCVE AI on September 15, 2026 at 06:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-802

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-802

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject connection when transport allocation fails handle_connect_req() returns without action when svc_rdma_create_xprt() fails to allocate the new transport. The CM core returns 0 for CONNECT_REQUEST events, so it does not destroy the new rdma_cm_id. Each allocation failure under memory pressure leaks one rdma_cm_id, and a remote peer driving connection attempts can amplify this. Reject the connection by returning a non-zero status from the CM event handler, which tells the CM core to destroy the orphaned cm_id.
Title svcrdma: Reject connection when transport allocation fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:44:10.769Z

Reserved: 2026-09-11T19:38:34.720Z

Link: CVE-2026-89531

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:35.987

Modified: 2026-09-11T20:19:35.987

Link: CVE-2026-89531

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:10Z

Links: CVE-2026-89531 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T06:45:16Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime