CVE-2026-89507

Source
https://cve.org/CVERecord?id=CVE-2026-89507
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89507.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89507
Downstream
Published
2026-09-11T19:43:54Z
Modified
2026-09-13T03:47:18Z
Summary
RDMA/ucma: Lock the handler in ucma_write_cm_event()
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/ucma: Lock the handler in ucma_write_cm_event()

ctx->file may only be changed under the handler lock and the xa_lock, which is what stops uevents being queued for a ctx while ucma_migrate_id() moves it to another file. The CM core takes that lock before invoking ucma_event_handler(), but the write() paths that queue uevents themselves do not.

ucma_write_cm_event() re-reads ctx->file for each of its four dereferences, so ucma_migrate_id() can swap it mid-sequence:

mutex_lock(&ctx->file->mut);			/* file A */
list_add_tail(&uevent->list, &ctx->file->event_list);	/* file B */
mutex_unlock(&ctx->file->mut);			/* file B */
wake_up_interruptible(&ctx->file->poll_wait);	/* file B */

The window is the mutex_lock() itself: the writer sleeps in it while the migration reassigns ctx->file. The list_add_tail() then runs on file B's event_list holding only file A's mutex:

list_add corruption. prev->next should be next (ffff888101320f30), but was ffff88814a08c418. (prev=ffff88814a075c18). kernel BUG at lib/list_debug.c:32! Call Trace: ucma_write_cm_event+0x36e/0x5e0

and file A's mut is left held forever, wedging its next writer in D state. The uevent is also stranded on a list ucma_cleanup_ctx_events() will not walk, so it outlives its context. /dev/infiniband/rdma_cm is 0666 and no RDMA device is involved, so an unprivileged user reaches all of this.

Take the handler lock, as ucma_cleanup_mc_events() does; ctx->cm_id is pinned by the ucma_get_ctx() reference.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89507.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a3c9d0fcd3715541bbf97da2ddde9d032e2fe6d5
Fixed
4f8bb11dd2ff365e7cff1c9964ab4607292d364e
Fixed
0be1955040a2eceed0ecfc387fdc92305411d273
Fixed
f4cc21c6a8e9d392871477f9fd98d68e5ad80272

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89507.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.18.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89507.json"