{"id":"CVE-2026-89534","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-89534","summary":"svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails\n\nWhen svc_rdma_listen_handler() handles RDMA_CM_EVENT_ADDR_CHANGE,\nit creates a replacement listener cm_id and returns 1, telling\nthe CM core to destroy the old one. If the replacement allocation\nfails, sc_cm_id still points at the old cm_id that the CM core is\nabout to destroy. Any subsequent dereference of sc_cm_id --\nsuch as svc_rdma_detach()'s rdma_disconnect() call -- is a\nuse-after-free.\n\nNULL sc_cm_id on the failure path and guard svc_rdma_detach()'s\nrdma_disconnect() call against NULL so that the listener can\nbe torn down safely when the server shuts down.","published":"2026-09-11T19:44:12.987Z","modified":"2026-09-14T03:46:12.073686536Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"7.2.4"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/01500306e1d50de7ca7a2cdcdfa28ac0523eb747"},{"type":"WEB","url":"https://git.kernel.org/stable/c/673e358ab7c11f8cec223c6a36a793056a67facd"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89534.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89534"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-14T03:46:12.073686536Z"}}