Description
In the Linux kernel, the following vulnerability has been resolved:

rapidio: mport_cdev: fix use-after-free in dma_req_free()

dma_req_free() acquires buf_mutex through req->map, drops the mapping
reference with kref_put(), and then dereferences req->map again to unlock
the mutex.

If kref_put() drops the last reference, mport_release_mapping() frees the
mapping, and the subsequent mutex_unlock() dereferences a freed object.
This is a use-after-free.

Fix this by caching map and md before kref_put(), clearing req->map while
holding buf_mutex, and using the cached md for mutex unlocking.

The bug is reachable from userspace via the RapidIO mport character device
interface.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to potential kernel crash or privilege escalation
Action: Apply Patch
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability is a use‑after‑free in the Linux kernel’s RapidIO mport character device module. When a user space program frees the last reference to a DMA mapping, the kernel releases the mapping object and then incorrectly attempts to dereference it, potentially causing memory corruption that can crash the kernel or result in privilege escalation. This weakness is classified under CWE‑825.

Affected Systems

Based on the description, it is inferred that the bug resides in the Linux kernel,port character device before the commit that caches the mapping and the mutex. No specific kernel version is listed, so any Linux deployment that has the mport interface and has not applied the patch is vulnerable.

Risk and Exploitability

Based on the description, it is inferred that the likely attack vector is local interaction with the RapidIO mport character device from userspace. The CVSS score is 7.8, indicating a high severity, and the vulnerability is not in the CISA KE1% indicates a very low probability of exploitation. Attackers can trigger the use‑after‑free by interacting with the RapidIO mport character device from userspace, which requires local access to that device. Because the impact rises to a kernel panic or privilege escalation if the attacker can execute arbitrary code on the system.

Generated by OpenCVE AI on September 15, 2026 at 19:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that fixes.
  • If an upgrade is not feasible immediately, unmount to prevent exploitation.
  • Ensure that the mport character device is accessible only to privileged users and that non‑privileged users cannot open it.

Generated by OpenCVE AI on September 15, 2026 at 19:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: rapidio: mport_cdev: fix use-after-free in dma_req_free() dma_req_free() acquires buf_mutex through req->map, drops the mapping reference with kref_put(), and then dereferences req->map again to unlock the mutex. If kref_put() drops the last reference, mport_release_mapping() frees the mapping, and the subsequent mutex_unlock() dereferences a freed object. This is a use-after-free. Fix this by caching map and md before kref_put(), clearing req->map while holding buf_mutex, and using the cached md for mutex unlocking. The bug is reachable from userspace via the RapidIO mport character device interface.
Title rapidio: mport_cdev: fix use-after-free in dma_req_free()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:25.695Z

Reserved: 2026-09-11T19:38:34.761Z

Link: CVE-2026-89742

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:04.863

Modified: 2026-09-14T13:19:23.040

Link: CVE-2026-89742

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:48Z

Links: CVE-2026-89742 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference