---
cve: "CVE-2026-89798"
severity: "LOW"
cvss: 3.1
epss: "4.1%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-09-16 11:16:44"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T05:39:08+02:00"
---

# CVE-2026-89798

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

rpcrdma: arm rn_done before publishing the notification

rpcrdma_rn_register() inserts @rn into rd_xa with xa_alloc() before
storing the caller's callback in rn->rn_done. The xarray makes @rn
reachable to rpcrdma_remove_one(), which walks rd_xa and invokes
rn->rn_done(rn) for every registered notification. A device removal
that races a fresh registration can therefore observe @rn with
rn_done still NULL, because the notification objects are zero
allocated by their owners, and call through a NULL function pointer.

Store rn->rn_done before xa_alloc() publishes @rn. The xarray's
store-side and load-side ordering then guarantees that any CPU which
finds @rn in rd_xa also observes the armed callback.

rpcrdma_rn_unregister() treats a non-NULL rn_done as the sentinel
for a completed registration, so the early store must not survive a
failed registration. Clear rn_done again when xa_alloc() fails.
Were it left set, the failed-accept cleanup path would call
rpcrdma_rn_unregister() on an @rn that was never inserted, erasing
an unrelated rd_xa slot and underflowing rd_kref.

## Patch verfügbar (OSV)

- Kernel ≥ 6.18.51
- Kernel ≥ 7.2.5

## Referenzen

- <https://git.kernel.org/stable/c/3c97b8e76ca2bba9e8770571413aed694068e78e>
- <https://git.kernel.org/stable/c/ea0408273ccf5df1fb52d9a1b9db4d31600dcb36>
- <https://git.kernel.org/stable/c/5b06f706374c37375bdff9d21cc10e61df925a92>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-89798) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
