CVE-2026-89543
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir
Normal client creation goes through rpc_setup_pipedir(), which records clnt->pipefs_sb, but the mount-event path in __rpc_clnt_handle_event() calls rpc_setup_pipedir_sb() directly and never refreshes that field. The umount path also removes the directory without clearing clnt->pipefs_sb.
After a late pipefs mount or any remount, rpc_clnt_remove_pipedir() compares the current superblock against a stale pipefs_sb pointer and skips cleanup, leaving pipefs dentries whose inode private data still points at a freed rpc_clnt, leading to a potential use-after-free during subsequent rpc_info_open() or rpc_show_info() calls.
Fix this by properly updating clnt->pipefs_sb upon mount events and clearing it during unmount or failure paths.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | bfca5fb4e97c46503ddfc582335917b0cc228264 < e769fcde3cc73e847b1eb3acd40c04a291cb0c0c | affected |
| Linux | Linux | bfca5fb4e97c46503ddfc582335917b0cc228264 < cdf7a233cb94774b0e7df42d9157077983f5022c | affected |
| Linux | Linux | bfca5fb4e97c46503ddfc582335917b0cc228264 < 932a8cf6abb2b2f8677b79153a823108d8861fe2 | affected |
| Linux | Linux | 17866066b8ac1cc38fb449670bc15dc9fee4b40a | affected |
| Linux | Linux | 7d61d1da2ed1f682c41cae0c8d4719cdaccee5c5 | affected |
| Linux | Linux | dedf2a0eb9448ae73b270743e6ea9b108189df46 | affected |
| Linux | Linux | 194454afa6aa9d6ed74f0c57127bc8beb27c20df | affected |
| Linux | Linux | 7749fd2dbef72a52b5c9ffdbf877691950ed4680 | affected |
| Linux | Linux | 1cdb52ffd6600a37bd355d8dce58ecd03e55e618 | affected |
| Linux | Linux | cc2e7ebbeb1d0601f7f3c8d93b78fcc03a95e44a | affected |
| Linux | Linux | 4.19.318 < 4.20 | affected |
| Linux | Linux | 5.4.280 < 5.5 | affected |
| Linux | Linux | 5.10.202 < 5.11 | affected |
| Linux | Linux | 5.15.140 < 5.16 | affected |
| Linux | Linux | 6.1.64 < 6.2 | affected |
| Linux | Linux | 6.5.13 < 6.6 | affected |
| Linux | Linux | 6.6.3 < 6.7 | affected |
| Linux | Linux | 6.7 | affected |
| Linux | Linux | 0 < 6.7 | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/e769fcde3cc73e847b1eb3acd40c04a291cb0c0c
- https://git.kernel.org/stable/c/cdf7a233cb94774b0e7df42d9157077983f5022c
- https://git.kernel.org/stable/c/932a8cf6abb2b2f8677b79153a823108d8861fe2
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.