{"id":"CVE-2026-89507","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-89507","summary":"RDMA/ucma: Lock the handler in ucma_write_cm_event()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/ucma: Lock the handler in ucma_write_cm_event()\n\nctx->file may only be changed under the handler lock and the xa_lock, which\nis what stops uevents being queued for a ctx while ucma_migrate_id() moves\nit to another file.  The CM core takes that lock before invoking\nucma_event_handler(), but the write() paths that queue uevents themselves\ndo not.\n\nucma_write_cm_event() re-reads ctx->file for each of its four dereferences,\nso ucma_migrate_id() can swap it mid-sequence:\n\n\tmutex_lock(&ctx->file->mut);\t\t\t/* file A */\n\tlist_add_tail(&uevent->list, &ctx->file->event_list);\t/* file B */\n\tmutex_unlock(&ctx->file->mut);\t\t\t/* file B */\n\twake_up_interruptible(&ctx->file->poll_wait);\t/* file B */\n\nThe window is the mutex_lock() itself: the writer sleeps in it while the\nmigration reassigns ctx->file.  The list_add_tail() then runs on file B's\nevent_list holding only file A's mutex:\n\n  list_add corruption. prev->next should be next (ffff888101320f30),\n    but was ffff88814a08c418. (prev=ffff88814a075c18).\n  kernel BUG at lib/list_debug.c:32!\n  Call Trace:\n   ucma_write_cm_event+0x36e/0x5e0\n\nand file A's mut is left held forever, wedging its next writer in D state.\nThe uevent is also stranded on a list ucma_cleanup_ctx_events() will not\nwalk, so it outlives its context.  /dev/infiniband/rdma_cm is 0666 and no\nRDMA device is involved, so an unprivileged user reaches all of this.\n\nTake the handler lock, as ucma_cleanup_mc_events() does; ctx->cm_id is\npinned by the ucma_get_ctx() reference.","published":"2026-09-11T19:43:54.013Z","modified":"2026-09-14T03:46:09.460145669Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.18.50"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0be1955040a2eceed0ecfc387fdc92305411d273"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4f8bb11dd2ff365e7cff1c9964ab4607292d364e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f4cc21c6a8e9d392871477f9fd98d68e5ad80272"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89507.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89507"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-14T03:46:09.460145669Z"}}