---
cve: "CVE-2026-72491"
severity: "CRITICAL"
cvss: 9.8
epss: "0.7%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-08-15 06:22:23"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-10-09T06:06:41+02:00"
---

# CVE-2026-72491

> 9.8 CRITICAL

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

net/9p: fix race condition on rdma->state in trans_rdma.c

The rdma->state field is modified without holding req_lock in both
recv_done() and p9_cm_event_handler(), while rdma_request() accesses
the same field under the req_lock spinlock. This inconsistent locking
creates a race condition:

- recv_done() running in softirq completion context sets
  rdma->state = P9_RDMA_FLUSHING without acquiring req_lock

- p9_cm_event_handler() modifies rdma->state at multiple points
  (ADDR_RESOLVED, ROUTE_RESOLVED, ESTABLISHED, CLOSED) without
  req_lock

- rdma_request() uses spin_lock_irqsave(&rdma->req_lock, flags) to
  protect the read-modify-write of rdma->state

The race can cause lost state transitions: recv_done() or the CM
event handler could set state to FLUSHING/CLOSED while rdma_request()
is concurrently checking or modifying state under the lock, leading to
the FLUSHING transition being silently overwritten by CLOSING. This
corrupts the connection state machine and can cause use-after-free on
RDMA request objects during teardown.

Fix by adding req_lock protection to all rdma->state modifications in
recv_done() and p9_cm_event_handler(), matching the pattern already
used in rdma_request(). Use spin_lock_irqsave/spin_unlock_irqrestore
in the CM event handler since it can race with recv_done() which runs
in softirq context.

Tested with a kernel module that races two threads (simulating
rdma_request and recv_done/CM handler) on rdma->state with proper
locking: 5.5M+ FLUSHING writes over 27M iterations with 0 lost
transitions.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 5.10.261
- Kernel ≥ 5.15.212
- Kernel ≥ 6.1.178
- Kernel ≥ 6.6.145
- Kernel ≥ 6.12.97
- Kernel ≥ 6.18.40
- Kernel ≥ 7.1.5

## BSI-Hinweise (deutsch)

- [Linux Kernel: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-2852) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service herbeizuführen oder einen nicht näher spezifizierten Angriff durchzuführen.

## Referenzen

- <https://git.kernel.org/stable/c/4cee2b8766045059d5e0b8114837b4a8efe827ac>
- <https://git.kernel.org/stable/c/5424138848eb7d7d8a7196676e90a2cbf2142454>
- <https://git.kernel.org/stable/c/3970a19a80de530b801b6256354d4a529a9a2d6c>
- <https://git.kernel.org/stable/c/8aadc136d8e8d8fc95d7982d213cfe2234dfcf2b>
- <https://git.kernel.org/stable/c/151f8cf5b23d8a534d884432a82a6d54d5a61989>
- <https://git.kernel.org/stable/c/13bf9879b778b2f4b260b45bed18f31806120d1e>
- <https://git.kernel.org/stable/c/ebbcbe5c0db215feecc17def06178da443f4eea6>
- <https://git.kernel.org/stable/c/7d54894a1ee265a72d70f7cae1da6cc774cccc71>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/sicherheitsluecken/cve-2026-72491/) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
