Description
In the Linux kernel, the following vulnerability has been resolved:

sunrpc: route to a populated pool in svc_pool_for_cpu()

svc_set_num_threads() spreads the requested threads evenly across the
service's pools (base = nrservs / sv_nrpools). When a service runs
fewer threads than it has pools -- e.g. an nfsd configured with fewer
threads than the host has NUMA nodes while running in "pernode" or
"percpu" mode -- the trailing pools are left with no threads at all.

svc_xprt_enqueue() selects a pool from the CPU servicing the transport,
queues the transport on that pool's sp_xprts, and only wakes a thread
from the same pool. Each thread services exclusively its own pool, so a
transport that lands on a threadless pool is enqueued on sp_xprts and
never picked up: the connection hangs indefinitely.

Have svc_pool_for_cpu() skip pools that currently have no threads,
falling back to the next populated pool. This trades NUMA locality for
a guarantee that the work is actually serviced. sp_nrthreads is only
updated under the service mutex; the lockless read here is a best-effort
routing hint, so annotate it with data_race().
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, the Sun RPC service failed to properly distribute its worker threads across CPU‑specific pools when the configured number of threads was less than the number of available pools. An incoming RPC request is routed to the pool associated with the CPU handling the transport. If that pool has no threads, the request stays queued forever because no worker can pick it up, resulting in an indefinitely hanging connection. This flaw is a classic instance of resource starvation (CWE‑821) and results in a denial of service for clients that rely on the RPC service.

Affected Systems

Any Linux kernel installation that runs the Sun RPC NFS server in NUMA‑aware mode (pernode or percpu) with fewer service threads than CPU pools may be affected. The report does not list specific kernel versions, so any kernel prior to the fix that uses the vulnerable svc_pool_for_cpu logic could suffer the hang. Linux distributions shipping earlier kernel versions are therefore potentially vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5 and an EPSS score of less than 1 %. It is not listed in the CISA KEV catalog. An attacker can exploit the flaw by sending a series of RPC requests from a client that targets the vulnerable NFS mount; when a request is routed to an empty pool the connection never completes, causing the server to consume resources and degrade availability. Based on the description, it is inferred that the attack vector would likely involve remote network traffic to the Sun RPC service.

Generated by OpenCVE AI on September 15, 2026 at 21:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel that patches svc_pool_for_cpu to skip empty pools during dispatch.
  • Configure the NFS daemon to set svc_num_threads to at least the number of CPU pools, or disable pernode/percpu mode when it is not required.
  • Restrict access to Sun RPC ports (111/UDP and TCP) by firewall policies so that only trusted hosts can connect to the service.

Generated by OpenCVE AI on September 15, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 12 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-821
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: sunrpc: route to a populated pool in svc_pool_for_cpu() svc_set_num_threads() spreads the requested threads evenly across the service's pools (base = nrservs / sv_nrpools). When a service runs fewer threads than it has pools -- e.g. an nfsd configured with fewer threads than the host has NUMA nodes while running in "pernode" or "percpu" mode -- the trailing pools are left with no threads at all. svc_xprt_enqueue() selects a pool from the CPU servicing the transport, queues the transport on that pool's sp_xprts, and only wakes a thread from the same pool. Each thread services exclusively its own pool, so a transport that lands on a threadless pool is enqueued on sp_xprts and never picked up: the connection hangs indefinitely. Have svc_pool_for_cpu() skip pools that currently have no threads, falling back to the next populated pool. This trades NUMA locality for a guarantee that the work is actually serviced. sp_nrthreads is only updated under the service mutex; the lockless read here is a best-effort routing hint, so annotate it with data_race().
Title sunrpc: route to a populated pool in svc_pool_for_cpu()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:52.566Z

Reserved: 2026-09-11T19:38:34.723Z

Link: CVE-2026-89549

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:38.373

Modified: 2026-09-14T13:19:09.857

Link: CVE-2026-89549

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:23Z

Links: CVE-2026-89549 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses
  • CWE-821

    Incorrect Synchronization