« Volver al listado

CVE-2026-89548

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: always drain cache_cleaner before destroying a cache_detail

sunrpc_destroy_cache_detail() only cancels the global cache_cleaner delayed_work when cache_list is empty. During per-netns teardown cache_list is never empty because init_net's caches remain registered, so the cancel never fires. After unlink, the caller proceeds to cache_destroy_net() which kfrees the cache_detail while cache_clean() may still hold a dangling pointer to it. The result is a use-after-free: cache_dequeue() takes cd->queue_lock on freed memory, and cache_put() dereferences cd->cache_put as a function pointer from freed slab.

Leer descripción completaMostrar menos

Drop the list_empty guard so that cancel_delayed_work_sync() always runs, ensuring any in-flight cache_clean() completes before the cache_detail is freed. Re-arm the cleaner afterwards if other caches are still registered.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89548",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "820f9442e711a81749e70c40f149fc54c4ce0ca8",
              "lessThan": "dec787a15c96a5665e9ffc61b429a6a4ab26e6b9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "820f9442e711a81749e70c40f149fc54c4ce0ca8",
              "lessThan": "5eea874a696201c31e7c2d7badbfa0d90e9961b5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "820f9442e711a81749e70c40f149fc54c4ce0ca8",
              "lessThan": "cf239de7fdcc8336259b01ea4bcf650dadad1040",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "820f9442e711a81749e70c40f149fc54c4ce0ca8",
              "lessThan": "6d74ecc2be120a0c300b224b7649fe93c0453714",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "820f9442e711a81749e70c40f149fc54c4ce0ca8",
              "lessThan": "9d44836f60c8c29bcdb1471fd9202387c642a890",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "820f9442e711a81749e70c40f149fc54c4ce0ca8",
              "lessThan": "2e861ce2aaa468351a6a47c4cbb4971ebb740c7b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "820f9442e711a81749e70c40f149fc54c4ce0ca8",
              "lessThan": "3d60fdf951143d6ef4e352e2f8eb852286701726",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "820f9442e711a81749e70c40f149fc54c4ce0ca8",
              "lessThan": "f42d0fda0c67695db6bc704b04b7c10240805377",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/sunrpc/cache.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/sunrpc/cache.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:38.250",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2e861ce2aaa468351a6a47c4cbb4971ebb740c7b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3d60fdf951143d6ef4e352e2f8eb852286701726",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5eea874a696201c31e7c2d7badbfa0d90e9961b5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6d74ecc2be120a0c300b224b7649fe93c0453714",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9d44836f60c8c29bcdb1471fd9202387c642a890",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cf239de7fdcc8336259b01ea4bcf650dadad1040",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dec787a15c96a5665e9ffc61b429a6a4ab26e6b9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f42d0fda0c67695db6bc704b04b7c10240805377",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: always drain cache_cleaner before destroying a cache_detail\n\nsunrpc_destroy_cache_detail() only cancels the global cache_cleaner\ndelayed_work when cache_list is empty.  During per-netns teardown\ncache_list is never empty because init_net's caches remain registered,\nso the cancel never fires.  After unlink, the caller proceeds to\ncache_destroy_net() which kfrees the cache_detail while cache_clean()\nmay still hold a dangling pointer to it.  The result is a\nuse-after-free: cache_dequeue() takes cd->queue_lock on freed memory,\nand cache_put() dereferences cd->cache_put as a function pointer from\nfreed slab.\n\nDrop the list_empty guard so that cancel_delayed_work_sync() always\nruns, ensuring any in-flight cache_clean() completes before the\ncache_detail is freed.  Re-arm the cleaner afterwards if other caches\nare still registered."
    }
  ],
  "lastModified": "2026-09-14T13:19:09.700",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}