Description
In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: always drain cache_cleaner before destroying a cache_detail

sunrpc_destroy_cache_detail() only cancels the global cache_cleaner
delayed_work when cache_list is empty. During per-netns teardown
cache_list is never empty because init_net's caches remain registered,
so the cancel never fires. After unlink, the caller proceeds to
cache_destroy_net() which kfrees the cache_detail while cache_clean()
may still hold a dangling pointer to it. The result is a
use-after-free: cache_dequeue() takes cd->queue_lock on freed memory,
and cache_put() dereferences cd->cache_put as a function pointer from
freed slab.

Drop the list_empty guard so that cancel_delayed_work_sync() always
runs, ensuring any in-flight cache_clean() completes before the
cache_detail is freed. Re-arm the cleaner afterwards if other caches
are still registered.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel code execution
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free flaw exists in the SUNRPC cache cleanup routine of the Linux kernel; the bug causes a freed cache_detail structure to be accessed by a background cleaner work item, leading to corruption of kernel data structures and the potential for arbitrary code execution at kernel privilege level, as indicated by its classification as CWE‑825.

Affected Systems

The vulnerability affects the SUNRPC subsystem in the Linux kernel, which manages RPC transmission caches across network namespaces. Any Linux kernel branch that loads this subsystem and handles RPC traffic could be exposed; however, the data does not provide specific affected versions, so version information is missing. System administrators should verify that the SUNRPC module or rpcbind service is installed and functioning, as these components provide the attack surface.

Risk and Exploitability

The CVSS score of 7.8 signals a high‑severity flaw, and the EPSS score of < 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves exploiting the use‑after‑free during SUNRPC cache cleanup, which could be triggered by an attacker sending crafted SUNRPC traffic or manipulating RPC connection teardown, potentially leading to kernel privilege execution if successful.

Generated by OpenCVE AI on September 15, 2026 at 22:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that removes the list_empty guard and ensures the cache_cleaner work is cancelled before a cache_detail is freed; the patch is included in the kernel commit references provided.
  • Reboot the system so the patched kernel and cleaned up cache structures take effect immediately.
  • If a kernel upgrade cannot be applied right away, limit or block SunRPC traffic by disabling the rpcbind service requests on port 111, thereby reducing the attack surface until the fix is applied.

Generated by OpenCVE AI on September 15, 2026 at 22:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Sat, 12 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: SUNRPC: always drain cache_cleaner before destroying a cache_detail sunrpc_destroy_cache_detail() only cancels the global cache_cleaner delayed_work when cache_list is empty. During per-netns teardown cache_list is never empty because init_net's caches remain registered, so the cancel never fires. After unlink, the caller proceeds to cache_destroy_net() which kfrees the cache_detail while cache_clean() may still hold a dangling pointer to it. The result is a use-after-free: cache_dequeue() takes cd->queue_lock on freed memory, and cache_put() dereferences cd->cache_put as a function pointer from freed slab. Drop the list_empty guard so that cancel_delayed_work_sync() always runs, ensuring any in-flight cache_clean() completes before the cache_detail is freed. Re-arm the cleaner afterwards if other caches are still registered.
Title SUNRPC: always drain cache_cleaner before destroying a cache_detail
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:51.491Z

Reserved: 2026-09-11T19:38:34.723Z

Link: CVE-2026-89548

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:38.250

Modified: 2026-09-14T13:19:09.700

Link: CVE-2026-89548

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:44:23Z

Links: CVE-2026-89548 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:45:07Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference