Answer in brief
CVE-2026-89543 records a Unknown severity vulnerability in sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bfca5fb4e97c46503ddfc582335917b0cc228264 <e769fcde3cc73e847b1eb3acd40c04a291cb0c0c || >=bfca5fb4e97c46503ddfc582335917b0cc228264 <cdf7a233cb94774b0e7df42d9157077983f5022c || >=bfca5fb4e97c46503ddfc582335917b0cc228264 <932a8cf6abb2b2f8677b79153a823108d8861fe2 || 17866066b8ac1cc38fb449670bc15dc9fee4b40a || 7d61d1da2ed1f682c41cae0c8d4719cdaccee5c5 || dedf2a0eb9448ae73b270743e6ea9b108189df46 || 194454afa6aa9d6ed74f0c57127bc8beb27c20df || 7749fd2dbef72a52b5c9ffdbf877691950ed4680 || 1cdb52ffd6600a37bd355d8dce58ecd03e55e618 || cc2e7ebbeb1d0601f7f3c8d93b78fcc03a95e44a || >=4.19.318 <4.20 || >=5.4.280 <5.5 || >=5.10.202 <5.11 || >=5.15.140 <5.16 || >=6.1.64 <6.2 || >=6.5.13 <6.6 || >=6.6.3 <6.7 | e769fcde3cc73e847b1eb3acd40c04a291cb0c0c, cdf7a233cb94774b0e7df42d9157077983f5022c, 932a8cf6abb2b2f8677b79153a823108d8861fe2, 4.20, 5.5, 5.11, 5.16, 6.2, 6.6, 6.7 |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir Normal client creation goes through rpc_setup_pipedir(), which records clnt->pipefs_sb, but the mount-event path in __rpc_clnt_handle_event() calls rpc_setup_pipedir_sb() directly and never refreshes that field. The umount path also removes the directory without clearing clnt->pipefs_sb. After a late pipefs mount or any remount, rpc_clnt_remove_pipedir() compares the current superblock against a stale pipefs_sb pointer and skips cleanup, leaving pipefs dentries whose inode private data still points at a freed rpc_clnt, leading to a potential use-after-free during subsequent rpc_info_open() or rpc_show_info() calls. Fix this by properly updating clnt->pipefs_sb upon mount events and clearing it during unmount or failure paths.
Quoted source text, attributed separately from HOL analysis.