Description
In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails

When svc_rdma_listen_handler() handles RDMA_CM_EVENT_ADDR_CHANGE,
it creates a replacement listener cm_id and returns 1, telling
the CM core to destroy the old one. If the replacement allocation
fails, sc_cm_id still points at the old cm_id that the CM core is
about to destroy. Any subsequent dereference of sc_cm_id --
such as svc_rdma_detach()'s rdma_disconnect() call -- is a
use-after-free.

NULL sc_cm_id on the failure path and guard svc_rdma_detach()'s
rdma_disconnect() call against NULL so that the listener can
be torn down safely when the server shuts down.
Published: 2026-09-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via use‑after‑free
Action: Patch
AI Analysis

Impact

This vulnerability in the Linux kernel’s svcrdma module is a use‑after‑free flaw identified as CWE‑825. When an RDMA address‑change event triggers the listener replacement handler, a new communication identifier (cm_id) is allocated. If that allocation fails, the existing pointer sc_cm_id is not cleared, leaving a dangling reference. A later detachment call dereferences this stale pointer, which can cause the kernel to crash and provide an attacker with a denial‑of‑service condition.

Affected Systems

This vulnerability affects Linux kernel svcrdma code before the change that cleared sc_cm_id on allocation failure. The issue remains in any kernel that has not yet incorporated the upstream commit providing the fix.

Risk and Exploitability

The CVSS score of 8.8 classifies this issue as high severity. The EPSS score of less than 1 % indicates a very low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Exposing a system to RDMA address‑change events is required for exploitation; this typically implies local or elevated privileges to trigger the event, but the description does not specify the exact prerequisites. The likely attack vector involves triggering an RDMA address‑change event that causes the listener replacement logic to run. Based on the description, it is inferred that the attacker would need to influence or observe RDMA events, which suggests a local or elevated‑privilege scenario.

Generated by OpenCVE AI on September 15, 2026 at 22:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel release that contains the upstream fix for svcrdma
  • If an upgrade is not possible, disable or unload the rdma kernel module to remove the attack surface
  • As a temporary workaround, apply the upstream patch that clears sc_cm_id on allocation failure and rebuild the kernel

Generated by OpenCVE AI on September 15, 2026 at 22:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails When svc_rdma_listen_handler() handles RDMA_CM_EVENT_ADDR_CHANGE, it creates a replacement listener cm_id and returns 1, telling the CM core to destroy the old one. If the replacement allocation fails, sc_cm_id still points at the old cm_id that the CM core is about to destroy. Any subsequent dereference of sc_cm_id -- such as svc_rdma_detach()'s rdma_disconnect() call -- is a use-after-free. NULL sc_cm_id on the failure path and guard svc_rdma_detach()'s rdma_disconnect() call against NULL so that the listener can be torn down safely when the server shuts down.
Title svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:30:31.103Z

Reserved: 2026-09-11T19:38:34.720Z

Link: CVE-2026-89534

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:36.390

Modified: 2026-09-13T07:17:15.650

Link: CVE-2026-89534

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:44:12Z

Links: CVE-2026-89534 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:45:07Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference