Answer in brief
CVE-2026-89545 records a Unknown severity vulnerability in sunrpc: defer rq_argp and rq_resp free until after RCU grace period. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=812443865c5fc255363d4a684a62c086af1addca <08bc49e0541260bf294962cf889a32a2d2713ad6 || >=812443865c5fc255363d4a684a62c086af1addca <e0c5693d3f9a5d4911735ab0e0eba4eecb1f1090 || >=812443865c5fc255363d4a684a62c086af1addca <c479bde671cbe2f9e152834a8b0eb7c3c295bbaf | 08bc49e0541260bf294962cf889a32a2d2713ad6, e0c5693d3f9a5d4911735ab0e0eba4eecb1f1090, c479bde671cbe2f9e152834a8b0eb7c3c295bbaf |
| Linux/Linuxgeneric | 3.19 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: sunrpc: defer rq_argp and rq_resp free until after RCU grace period svc_rqst_free() frees rqstp->rq_argp and rqstp->rq_resp synchronously via kfree(), but defers the rqstp struct free via kfree_rcu(). After svc_exit_thread() calls list_del_rcu() and svc_rqst_free(), there is a window where RCU readers that started before list_del_rcu() can still traverse the thread list and find the rqstp. These readers (e.g. nfsd_nl_rpc_status_get_dumpit()) dereference rqstp->rq_argp, which has already been freed — a use-after-free. Fix this by moving the kfree of rq_argp and rq_resp into an explicit call_rcu() callback alongside the struct free. Resources not accessed by RCU readers (bvec, buffer pages, scratch folio, auth_data) remain synchronously freed.
Quoted source text, attributed separately from HOL analysis.