{"id":"CVE-2026-72491","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-72491","summary":"net/9p: fix race condition on rdma->state in trans_rdma.c","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/9p: fix race condition on rdma->state in trans_rdma.c\n\nThe rdma->state field is modified without holding req_lock in both\nrecv_done() and p9_cm_event_handler(), while rdma_request() accesses\nthe same field under the req_lock spinlock. This inconsistent locking\ncreates a race condition:\n\n- recv_done() running in softirq completion context sets\n  rdma->state = P9_RDMA_FLUSHING without acquiring req_lock\n\n- p9_cm_event_handler() modifies rdma->state at multiple points\n  (ADDR_RESOLVED, ROUTE_RESOLVED, ESTABLISHED, CLOSED) without\n  req_lock\n\n- rdma_request() uses spin_lock_irqsave(&rdma->req_lock, flags) to\n  protect the read-modify-write of rdma->state\n\nThe race can cause lost state transitions: recv_done() or the CM\nevent handler could set state to FLUSHING/CLOSED while rdma_request()\nis concurrently checking or modifying state under the lock, leading to\nthe FLUSHING transition being silently overwritten by CLOSING. This\ncorrupts the connection state machine and can cause use-after-free on\nRDMA request objects during teardown.\n\nFix by adding req_lock protection to all rdma->state modifications in\nrecv_done() and p9_cm_event_handler(), matching the pattern already\nused in rdma_request(). Use spin_lock_irqsave/spin_unlock_irqrestore\nin the CM event handler since it can race with recv_done() which runs\nin softirq context.\n\nTested with a kernel module that races two threads (simulating\nrdma_request and recv_done/CM handler) on rdma->state with proper\nlocking: 5.5M+ FLUSHING writes over 27M iterations with 0 lost\ntransitions.","published":"2026-08-15T05:57:26.281Z","modified":"2026-08-18T03:56:26.824637853Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"5.10.261"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/13bf9879b778b2f4b260b45bed18f31806120d1e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/151f8cf5b23d8a534d884432a82a6d54d5a61989"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3970a19a80de530b801b6256354d4a529a9a2d6c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4cee2b8766045059d5e0b8114837b4a8efe827ac"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5424138848eb7d7d8a7196676e90a2cbf2142454"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7d54894a1ee265a72d70f7cae1da6cc774cccc71"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8aadc136d8e8d8fc95d7982d213cfe2234dfcf2b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ebbcbe5c0db215feecc17def06178da443f4eea6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72491.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72491"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T03:56:26.824637853Z"}}