CVE-2026-89548
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: always drain cache_cleaner before destroying a cache_detail
sunrpc_destroy_cache_detail() only cancels the global cache_cleaner delayed_work when cache_list is empty. During per-netns teardown cache_list is never empty because init_net's caches remain registered, so the cancel never fires. After unlink, the caller proceeds to cache_destroy_net() which kfrees the cache_detail while cache_clean() may still hold a dangling pointer to it. The result is a use-after-free: cache_dequeue() takes cd->queue_lock on freed memory, and cache_put() dereferences cd->cache_put as a function pointer from freed slab.
Drop the list_empty guard so that cancel_delayed_work_sync() always runs, ensuring any in-flight cache_clean() completes before the cache_detail is freed. Re-arm the cleaner afterwards if other caches are still registered.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 820f9442e711a81749e70c40f149fc54c4ce0ca8 < 9d44836f60c8c29bcdb1471fd9202387c642a890 | affected |
| Linux | Linux | 820f9442e711a81749e70c40f149fc54c4ce0ca8 < 2e861ce2aaa468351a6a47c4cbb4971ebb740c7b | affected |
| Linux | Linux | 820f9442e711a81749e70c40f149fc54c4ce0ca8 < 3d60fdf951143d6ef4e352e2f8eb852286701726 | affected |
| Linux | Linux | 820f9442e711a81749e70c40f149fc54c4ce0ca8 < f42d0fda0c67695db6bc704b04b7c10240805377 | affected |
| Linux | Linux | 3.4 | affected |
| Linux | Linux | 0 < 3.4 | unaffected |
| Linux | Linux | 6.12.109 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/9d44836f60c8c29bcdb1471fd9202387c642a890
- https://git.kernel.org/stable/c/2e861ce2aaa468351a6a47c4cbb4971ebb740c7b
- https://git.kernel.org/stable/c/3d60fdf951143d6ef4e352e2f8eb852286701726
- https://git.kernel.org/stable/c/f42d0fda0c67695db6bc704b04b7c10240805377
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.