Answer in brief
CVE-2026-89535 records a Unknown severity vulnerability in svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c4de97f7c45434985e5dbf2d6ccc9eca676e37fe <9f2f5d0999364c7070306cd422d8babc2621070d || >=c4de97f7c45434985e5dbf2d6ccc9eca676e37fe <cfca6eb3345ba4a23cf9a1153ad09bf19faabfc9 || >=c4de97f7c45434985e5dbf2d6ccc9eca676e37fe <4488e912973773d64368828acf3b8e39d93650ae | 9f2f5d0999364c7070306cd422d8babc2621070d, cfca6eb3345ba4a23cf9a1153ad09bf19faabfc9, 4488e912973773d64368828acf3b8e39d93650ae |
| Linux/Linuxgeneric | 6.12 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id svc_rdma_free() caches rdma->sc_cm_id->device before teardown, then calls rdma_destroy_id(sc_cm_id) which frees the cm_id. rpcrdma_rn_unregister() follows, but between those two calls the transport's sc_rn entry is still installed in the device's rd_xa. A concurrent ib_unregister_device walk can dispatch svc_rdma_xprt_done() against the now-freed sc_cm_id. Move rpcrdma_rn_unregister() before rdma_destroy_id() so the transport's notification entry is removed from the xarray before the cm_id it references is destroyed. Also guard the sc_cm_id dereference with a NULL check: the following patches introduce paths that reach svc_rdma_free() with sc_cm_id == NULL (listener create failure, ADDR_CHANGE replacement failure).
Quoted source text, attributed separately from HOL analysis.